Lucene search

K

Powerscripts Security Vulnerabilities

cve
cve

CVE-2009-0705

SQL injection vulnerability in news.php in PowerScripts PowerNews 2.5.4, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the newsid...

8.7AI Score

0.001EPSS

2009-02-23 03:30 PM
21
cve
cve

CVE-2009-0707

SQL injection vulnerability in admin/index.php in PowerClan 1.14a allows remote attackers to execute arbitrary SQL commands via the loginemail parameter (aka login field). NOTE: some of these details are obtained from third party...

8.7AI Score

0.001EPSS

2009-02-23 03:30 PM
21
cve
cve

CVE-2008-1534

Multiple directory traversal vulnerabilities in PowerPHPBoard 1.00b allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) settings[footer] parameter to footer.inc.php and the (2) settings[header] parameter to...

7.3AI Score

0.048EPSS

2008-03-28 06:44 PM
18
cve
cve

CVE-2008-1537

Directory traversal vulnerability in pb_inc/admincenter/index.php in PowerScripts PowerBook 1.21 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a...

7.2AI Score

0.043EPSS

2008-03-28 06:44 PM
20
cve
cve

CVE-2008-0742

Multiple directory traversal vulnerabilities in PowerScripts PowerNews 2.5.6 allow remote attackers to read and include arbitrary files via a .. (dot dot) in the (1) subpage parameter in (a) categories.inc.php, (b) news.inc.php, (c) other.inc.php, (d) permissions.inc.php, (e) templates.inc.php,...

6.9AI Score

0.013EPSS

2008-02-13 02:00 AM
18
cve
cve

CVE-2006-6715

PHP remote file inclusion vulnerability in footer.inc.php in PowerClan 1.14a and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the settings[footer]...

7.9AI Score

0.118EPSS

2006-12-23 01:28 AM
16
cve
cve

CVE-2006-1805

SQL injection vulnerability in member.php in PowerClan 1.14 allows remote attackers to execute arbitrary SQL commands via the memberid...

8.4AI Score

0.009EPSS

2006-04-18 10:02 AM
20
cve
cve

CVE-2000-0074

PowerScripts PlusMail CGI program allows remote attackers to execute commands via a password file with improper...

7.4AI Score

0.055EPSS

2000-02-04 05:00 AM
35
4