Lucene search

K

Wsn Security Vulnerabilities

cve
cve

CVE-2010-4006

Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch...

8.5AI Score

0.001EPSS

2010-11-03 08:00 PM
27
cve
cve

CVE-2008-6033

SQL injection vulnerability in comments.php in WSN Links 2.20 allows remote attackers to execute arbitrary SQL commands via the id...

8.7AI Score

0.001EPSS

2009-02-03 11:30 AM
19
cve
cve

CVE-2008-6031

SQL injection vulnerability in vote.php in WSN Links 2.22 and 2.23 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: it was later reported that 2.34 is also...

8.7AI Score

0.001EPSS

2009-02-03 11:30 AM
19
cve
cve

CVE-2008-6032

SQL injection vulnerability in comments.php in WSN Links Free 4.0.34P allows remote attackers to execute arbitrary SQL commands via the id...

8.7AI Score

0.001EPSS

2009-02-03 11:30 AM
23
cve
cve

CVE-2008-3555

Directory traversal vulnerability in index.php in (1) WSN Forum 4.1.43 and earlier, (2) Gallery 4.1.30 and earlier, (3) Knowledge Base (WSNKB) 4.1.36 and earlier, (4) Links 4.1.44 and earlier, and possibly (5) Classifieds before 4.1.30 allows remote attackers to include and execute arbitrary local....

7.3AI Score

0.018EPSS

2008-08-08 07:41 PM
18
cve
cve

CVE-2007-3981

SQL injection vulnerability in index.php in WSN Links Basic Edition allows remote attackers to execute arbitrary SQL commands via the catid parameter in a displaycat...

8.3AI Score

0.008EPSS

2007-07-25 05:30 PM
21
cve
cve

CVE-2006-5421

WSN Forum 1.3.4 and earlier allows remote attackers to execute arbitrary PHP code via a modified pathname in the pathtoconfig parameter that points to an avatar image that contains PHP code, which is then accessed from prestart.php. NOTE: this issue has been labeled remote file inclusion, but...

7.9AI Score

0.066EPSS

2006-10-20 02:07 PM
21
cve
cve

CVE-2005-3939

Multiple SQL injection vulnerabilities in WSN Knowledge Base 1.2.0 and earler allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) perpage, (3) ascdesc, and (4) orderlinks in a displaycat action in (a) index.php; and the (5) id parameter in (b) comments.php and (c)...

8.9AI Score

0.006EPSS

2005-12-01 11:00 AM
18
cve
cve

CVE-2005-3916

SQL injection vulnerability in memberlist.php in WSN Forum 1.21 allows remote attackers to execute arbitrary SQL commands via the id parameter in a profile...

8.8AI Score

0.006EPSS

2005-11-30 11:03 AM
17