Lucene search

K

Business Card Web Builder Security Vulnerabilities

cve
cve

CVE-2006-4946

PHP remote file inclusion vulnerability in include/startup.inc.php in CMSDevelopment Business Card Web Builder (BCWB) 0.99, and possibly 2.5 Beta and earlier, allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.

7.6AI Score

0.082EPSS

2006-09-23 01:07 AM
21
cve
cve

CVE-2006-5816

Multiple PHP remote file inclusion vulnerabilities in Dmitry Sheiko Business Card Web Builder (BCWB) 2.5 allow remote attackers to execute arbitrary PHP code via a URL in the root_path_admin parameter to (1) /include/startup.inc.php, (2) dcontent/default.css.php, or (3) system/default.css.php, diff...

7.6AI Score

0.082EPSS

2006-11-08 11:07 PM
23
cve
cve

CVE-2024-4529

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as deleting card categories via CSRF attacks

5CVSS

6.7AI Score

0.0004EPSS

2024-05-27 06:15 AM
27
cve
cve

CVE-2024-4530

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as editing card categories via CSRF attacks

6.7AI Score

0.0004EPSS

2024-05-27 06:15 AM
27
cve
cve

CVE-2024-4531

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as editing cards via CSRF attacks

7.1CVSS

6.7AI Score

0.0004EPSS

2024-05-27 06:15 AM
28
cve
cve

CVE-2024-4532

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as deleting cards via CSRF attacks

6.7AI Score

0.0004EPSS

2024-05-27 06:15 AM
28