Lucene search

K

Crea-book Security Vulnerabilities

cve
cve

CVE-2007-2314

Multiple SQL injection vulnerabilities in Crea-Book 1.0, and possibly earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) pseudo or (2) passe parameter to (a) configurer.php, (b) connect.php, (c) delete.php, (d) delete2.php, (e)...

8.1AI Score

0.008EPSS

2007-04-26 09:19 PM
23
cve
cve

CVE-2007-2001

Multiple direct static code injection vulnerabilities in admin/configurer2.php in Crea-Book 1.0 and earlier allow remote authenticated administrators to execute arbitrary PHP code via the "Fond de la page" (background color) field and other unspecified fields, which injects into...

7.6AI Score

0.004EPSS

2007-04-12 07:19 PM
20