Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
eggblog vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2007-5980
Cross-site scripting (XSS) vulnerability in home/rss.php in eggblog prior to 3.1.1 allows remote malicious users to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF).
Eggblog Eggblog
7.5
CVSSv2
CVE-2008-1626
SQL injection vulnerability in eggBlog prior to 4.0.1 allows remote malicious users to execute arbitrary SQL commands via an unspecified cookie. NOTE: this might overlap CVE-2008-0159.
Eggblog Eggblog
6.8
CVSSv2
CVE-2007-2978
Session fixation vulnerability in eggblog 3.1.0 and previous versions allows remote malicious users to hijack web sessions by setting the PHPSESSID parameter.
Eggblog Eggblog
6.8
CVSSv2
CVE-2008-0159
SQL injection vulnerability in index.php in eggBlog 3.1.0 and previous versions allows remote malicious users to execute arbitrary SQL commands via the eggblogpassword parameter in a cookie.
Eggblog Eggblog
1 EDB exploit
5
CVSSv2
CVE-2011-3732
eggBlog 4.1.2 allows remote malicious users to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by _lib/fckeditor/editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php ...
Eggblog Eggblog 4.1.2
7.5
CVSSv2
CVE-2006-2727
home/register.php in Eggblog prior to 3.0 allows remote malicious users to change the password of administrators and possibly other users via a modified username parameter.
Epic Designs Eggblog
Epic Designs Eggblog 2.0
Epic Designs Eggblog 3.0
6.4
CVSSv2
CVE-2006-2725
SQL injection vulnerability in rss/posts.php in Eggblog prior to 3.07 allows remote malicious users to execute arbitrary SQL commands via the id parameter.
Epic Designs Eggblog
1 EDB exploit
7.8
CVSSv2
CVE-2005-4546
search.php in eggblog 2.0 allows remote malicious users to obtain the full path via an invalid q parameter, as used by the Keyword and Search fields, possibly due to an SQL injection vulnerability.
Epic Designs Eggblog
4.3
CVSSv2
CVE-2005-4547
Cross-site scripting (XSS) vulnerability in home/search.php in eggblog 2.0 allows remote malicious users to execute arbitrary SQL commands via the q parameter, as used by the Keyword and Search fields.
Epic Designs Eggblog
7.5
CVSSv2
CVE-2006-0349
SQL injection vulnerability in eggblog 2.0 allows remote malicious users to execute arbitrary SQL commands via the id parameter to blog.php.
Epic Designs Eggblog 2.0
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
hardcoded
arbitrary code
CVE-2024-2404
CVE-2024-21111
CVE-2024-28627
CVE-2024-4073
information disclosure
CVE-2024-32780
CVE-2024-4040
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »