Vulnerabilities
Vulnerable Software
Geeklog:  >> Geeklog  >> 2.2.2  Security Vulnerabilities
Cross Site Scripting (XSS) vulnerability in Geeklog-Core geeklog v.2.2.2 allows a remote attacker to execute arbitrary code via a crafted payload to the grp_desc parameter of the admin/group.php component.
CVSS Score
4.8
EPSS Score
0.002
Published
2023-10-24
Cross Site Scripting (XSS) vulnerability in Geeklog-Core geeklog v.2.2.2 allows a remote attacker to execute arbitrary code via a crafted payload to the Service, and website URL to Ping parameters of the admin/trackback.php component.
CVSS Score
4.8
EPSS Score
0.001
Published
2023-10-24
Multiple cross-site scripting (XSS) vulnerabilities in Geeklog v2.2.2 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Mail Settings[backend], Mail Settings[host], Mail Settings[port] and Mail Settings[auth] parameters of the /admin/configuration.php.
CVSS Score
4.8
EPSS Score
0.001
Published
2023-07-13
Multiple cross-site scripting (XSS) vulnerabilities in Geeklog v2.2.2 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Rule and Route parameters of /admin/router.php.
CVSS Score
4.8
EPSS Score
0.001
Published
2023-07-13


Contact Us

Shodan ® - All rights reserved