Saphplesson
Arabless · 6 CVEs
SQL injection vulnerability in admin/login.php in SaphpLesson 4.0, when magic_quotes_gpc is disabled, allows remote att…
Aug 20, 2009
SQL injection vulnerability in saphplesson 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) fo…
Jun 6, 2006
Multiple SQL injection vulnerabilities in SaphpLesson 3.0 allow remote attackers to execute arbitrary SQL commands via…
May 9, 2006
SaphpLesson 3.0 does not initialize array variables, which allows remote attackers to obtain the full path via an non-a…
May 9, 2006
Cross-site scripting (XSS) vulnerability in search.php in SaphpLesson 3.0 allows remote attackers to inject arbitrary w…
Apr 11, 2006
SQL injection vulnerability in print.php in SaphpLesson 2.0 allows remote attackers to execute arbitrary SQL commands v…
Mar 28, 2006
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2009-2883 | SQL injection vulnerability in admin/login.php in SaphpLesson 4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands… | MEDIUM | 0.90% | Aug 20, 2009 |
| CVE-2006-2835 | SQL injection vulnerability in saphplesson 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) forumid parameter in add.php and (2) lessi… | HIGH | 1.28% | Jun 6, 2006 |
| CVE-2006-2279 | Multiple SQL injection vulnerabilities in SaphpLesson 3.0 allow remote attackers to execute arbitrary SQL commands via (1) the Find parameter in (a) search.php… | HIGH | 2.15% | May 9, 2006 |
| CVE-2006-2278 | SaphpLesson 3.0 does not initialize array variables, which allows remote attackers to obtain the full path via an non-array (1) hrow parameter to (a) show.php… | MEDIUM | 1.58% | May 9, 2006 |
| CVE-2006-1720 | Cross-site scripting (XSS) vulnerability in search.php in SaphpLesson 3.0 allows remote attackers to inject arbitrary web script or HTML via the Word parameter… | MEDIUM | 1.17% | Apr 11, 2006 |
| CVE-2006-1420 | SQL injection vulnerability in print.php in SaphpLesson 2.0 allows remote attackers to execute arbitrary SQL commands via the lessid parameter. | MEDIUM | 1.10% | Mar 28, 2006 |
Showing 1 to 6 of 6 CVEs