Vulnerabilities
Vulnerable Software
Phpee:  >> Pphlogger  >> 2.2.5  Security Vulnerabilities
Cross-site scripting (XSS) vulnerability in dspStats.php in PowerPhlogger 2.2.5 allows remote attackers to inject arbitrary web script or HTML via the edit parameter.
CVSS Score
4.3
EPSS Score
0.01
Published
2009-12-10
PowerPhlogger 2.2.5 allows remote attackers to obtain sensitive information via a direct request to (1) edCss.inc.php, (2) foot.inc.php, (3) get_csscolors.inc.php, (4) head.inc.php, (5) head_stuff.inc.php, (6) loglist.inc.php, and (7) pphlogger_send.inc.php in include/, which reveals the installation path in an error message.
CVSS Score
5.0
EPSS Score
0.003
Published
2009-12-10


Contact Us

Shodan ® - All rights reserved