Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
codeigniter codeigniter vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2015-5725
SQL injection vulnerability in the offset method in the Active Record class in CodeIgniter prior to 2.2.4 allows remote malicious users to execute arbitrary SQL commands via vectors involving the offset variable.
Codeigniter Codeigniter
6.1
CVSSv3
CVE-2013-4891
The xss_clean function in CodeIgniter prior to 2.1.4 might allow remote malicious users to bypass an intended protection mechanism and conduct cross-site scripting (XSS) attacks via an unclosed HTML tag.
Codeigniter Codeigniter
7.5
CVSSv3
CVE-2017-1000247
British Columbia Institute of Technology CodeIgniter 3.1.3 is vulnerable to HTTP Header Injection in the set_status_header() common function under Apache resulting in HTTP Header Injection flaws.
Codeigniter Codeigniter 3.1.3
9.8
CVSSv3
CVE-2014-8686
CodeIgniter prior to 2.2.0 makes it easier for malicious users to decode session cookies by leveraging fallback to a custom XOR-based encryption scheme when the Mcrypt extension for PHP is not available.
Codeigniter Codeigniter
1 EDB exploit
2 Articles
9.8
CVSSv3
CVE-2014-8684
CodeIgniter prior to 3.0 and Kohana 3.2.3 and previous versions and 3.3.x up to and including 3.3.2 make it easier for remote malicious users to spoof session cookies and consequently conduct PHP object injection attacks by leveraging use of standard string comparison operators t...
Kohanaframework Kohana 3.3.1
Codeigniter Codeigniter
Kohanaframework Kohana 3.3.0
Kohanaframework Kohana 3.2.3
1 EDB exploit
9.8
CVSSv3
CVE-2016-10131
system/libraries/Email.php in CodeIgniter prior to 3.1.3 allows remote malicious users to execute arbitrary code by leveraging control over the email->from field to insert sendmail command-line arguments.
Codeigniter Codeigniter
NA
CVE-2012-4236
Cross-site scripting (XSS) vulnerability in the refresh_page function in application/modules/_main/views/_top.php in Total Shop UK eCommerce Open Source prior to 2.1.2_p1 allows remote malicious users to inject arbitrary web script or HTML via the PATH_INFO.
Totalshopuk Ecommerce
Totalshopuk Ecommerce 2.1.1
Totalshopuk Ecommerce 2.1.0
Totalshopuk Ecommerce 2.0.3
Totalshopuk Ecommerce 2.0.2
Totalshopuk Ecommerce 1.5.2
Totalshopuk Ecommerce 1.7
Totalshopuk Ecommerce 1.7.0
Totalshopuk Ecommerce 1.6.3
Totalshopuk Ecommerce 1.6.2
Totalshopuk Ecommerce 1.3.1
Totalshopuk Ecommerce 1.3
Totalshopuk Ecommerce 1.2
Totalshopuk Ecommerce 1.1
Totalshopuk Ecommerce 1.0
Totalshopuk Ecommerce 1.5.1
Totalshopuk Ecommerce 1.5.0.1
Totalshopuk Ecommerce 1.5.0
Totalshopuk Ecommerce 2.0.0
Totalshopuk Ecommerce 1.7.1
Totalshopuk Ecommerce 1.6.1
Totalshopuk Ecommerce 1.5.4
1 EDB exploit
NA
CVE-2011-4025
ExpressionEngine version 2.2.2 and CodeIgniter version 2.0.3 suffer from filter bypass and cross site scripting vulnerabilities.
NA
CVE-2011-3719
CodeIgniter 1.7.2 allows remote malicious users to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/scaffolding/views/view.php and certain other files.
Codeigniter Codeigniter 1.7.2
NA
CVE-2007-3706
The _sanitize_globals function in CodeIgniter 1.5.3 prior to 20070628 allows remote malicious users to unset arbitrary global variables with unspecified impact, as demonstrated by a _SERVER cookie.
Codeigniter Codeigniter 1.5.3
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
validation
CVE-2012-1823
malicious code
CVE-2024-5770
CVE-2023-45866
CVE-2024-35687
local users
CVE-2024-31246
CVE-2024-35730
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »