Vulnerabilities
Vulnerable Software
Sangwan Kim:  Security Vulnerabilities
SQL injection vulnerability in admin/config.php in Bookmark4U 2.0 and 2.1 allows remote attackers to inject arbitrary SQL command via the sqlcmd parameter.
CVSS Score
7.5
EPSS Score
0.008
Published
2007-02-23
PHP remote file inclusion vulnerability in config.php in Sangwan Kim phpIndexPage 1.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the env[inc_path] parameter.
CVSS Score
6.8
EPSS Score
0.026
Published
2007-01-25
PHP remote file inclusion vulnerability in Bookmark4U 2.0.0 and earlier allows remote attackers to include arbitrary PHP files via the include_prefix parameter in (1) inc/dbase.php, (2) inc/config.php, (3) inc/common.php, and (4) inc/function.php. NOTE: it has been reported that the inc directory is protected by a .htaccess file, so this issue only applies in certain environments or configurations.
CVSS Score
7.5
EPSS Score
0.051
Published
2006-06-07
PHP remote file inclusion vulnerability in Bookmark4U 1.8.3 allows remote attackers to execute arbitrary PHP code viaa URL in the prefix parameter to (1) dbase.php, (2) config.php, or (3) common.load.php.
CVSS Score
7.5
EPSS Score
0.009
Published
2003-12-31


Contact Us

Shodan ® - All rights reserved