Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
codeigniter codeigniter vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2015-5725
SQL injection vulnerability in the offset method in the Active Record class in CodeIgniter prior to 2.2.4 allows remote malicious users to execute arbitrary SQL commands via vectors involving the offset variable.
Codeigniter Codeigniter
4.3
CVSSv2
CVE-2013-4891
The xss_clean function in CodeIgniter prior to 2.1.4 might allow remote malicious users to bypass an intended protection mechanism and conduct cross-site scripting (XSS) attacks via an unclosed HTML tag.
Codeigniter Codeigniter
5
CVSSv2
CVE-2017-1000247
British Columbia Institute of Technology CodeIgniter 3.1.3 is vulnerable to HTTP Header Injection in the set_status_header() common function under Apache resulting in HTTP Header Injection flaws.
Codeigniter Codeigniter 3.1.3
7.5
CVSSv2
CVE-2014-8684
CodeIgniter prior to 3.0 and Kohana 3.2.3 and previous versions and 3.3.x up to and including 3.3.2 make it easier for remote malicious users to spoof session cookies and consequently conduct PHP object injection attacks by leveraging use of standard string comparison operators t...
Kohanaframework Kohana 3.3.1
Codeigniter Codeigniter
Kohanaframework Kohana 3.3.0
Kohanaframework Kohana 3.2.3
1 EDB exploit
5
CVSSv2
CVE-2014-8686
CodeIgniter prior to 2.2.0 makes it easier for malicious users to decode session cookies by leveraging fallback to a custom XOR-based encryption scheme when the Mcrypt extension for PHP is not available.
Codeigniter Codeigniter
1 EDB exploit
2 Articles
7.5
CVSSv2
CVE-2016-10131
system/libraries/Email.php in CodeIgniter prior to 3.1.3 allows remote malicious users to execute arbitrary code by leveraging control over the email->from field to insert sendmail command-line arguments.
Codeigniter Codeigniter
4.3
CVSSv2
CVE-2012-4236
Cross-site scripting (XSS) vulnerability in the refresh_page function in application/modules/_main/views/_top.php in Total Shop UK eCommerce Open Source prior to 2.1.2_p1 allows remote malicious users to inject arbitrary web script or HTML via the PATH_INFO.
Totalshopuk Ecommerce
Totalshopuk Ecommerce 2.1.1
Totalshopuk Ecommerce 2.1.0
Totalshopuk Ecommerce 2.0.3
Totalshopuk Ecommerce 2.0.2
Totalshopuk Ecommerce 1.5.2
Totalshopuk Ecommerce 1.7
Totalshopuk Ecommerce 1.7.0
Totalshopuk Ecommerce 1.6.3
Totalshopuk Ecommerce 1.6.2
Totalshopuk Ecommerce 1.3.1
Totalshopuk Ecommerce 1.3
Totalshopuk Ecommerce 1.2
Totalshopuk Ecommerce 1.1
Totalshopuk Ecommerce 1.0
Totalshopuk Ecommerce 1.5.1
Totalshopuk Ecommerce 1.5.0.1
Totalshopuk Ecommerce 1.5.0
Totalshopuk Ecommerce 2.0.0
Totalshopuk Ecommerce 1.7.1
Totalshopuk Ecommerce 1.6.1
Totalshopuk Ecommerce 1.5.4
1 EDB exploit
NA
CVE-2011-4025
ExpressionEngine version 2.2.2 and CodeIgniter version 2.0.3 suffer from filter bypass and cross site scripting vulnerabilities.
5
CVSSv2
CVE-2011-3719
CodeIgniter 1.7.2 allows remote malicious users to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/scaffolding/views/view.php and certain other files.
Codeigniter Codeigniter 1.7.2
2.1
CVSSv2
CVE-2007-3706
The _sanitize_globals function in CodeIgniter 1.5.3 prior to 20070628 allows remote malicious users to unset arbitrary global variables with unspecified impact, as demonstrated by a _SERVER cookie.
Codeigniter Codeigniter 1.5.3
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3380
CVE-2024-1694
local file inclusion
CVE-2024-5645
CVE-2024-24919
XSS
CVE-2024-36774
CVE-2024-21306
SQL
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »