Vulnerabilities
Vulnerable Software
Phpee:  Security Vulnerabilities
Cross-site scripting (XSS) vulnerability in dspStats.php in PowerPhlogger 2.2.5 allows remote attackers to inject arbitrary web script or HTML via the edit parameter.
CVSS Score
4.3
EPSS Score
0.01
Published
2009-12-10
PowerPhlogger 2.2.5 allows remote attackers to obtain sensitive information via a direct request to (1) edCss.inc.php, (2) foot.inc.php, (3) get_csscolors.inc.php, (4) head.inc.php, (5) head_stuff.inc.php, (6) loglist.inc.php, and (7) pphlogger_send.inc.php in include/, which reveals the installation path in an error message.
CVSS Score
5.0
EPSS Score
0.003
Published
2009-12-10
SQL injection vulnerability in include/get_userdata.php in Power Phlogger (PPhlogger) 2.2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter to login.php.
CVSS Score
7.5
EPSS Score
0.008
Published
2007-06-26
Cross-site scripting (XSS) vulnerability in YA Book 0.98-alpha allows remote attackers to inject arbitrary web script or HTML via the City field in a sign action in index.php.
CVSS Score
6.8
EPSS Score
0.006
Published
2007-04-25


Contact Us

Shodan ® - All rights reserved