Stud.ip
Studip · 2 CVEs
CVE-2023-50982
CRITICAL
Stud.IP 5.x through 5.3.3 allows XSS with resultant upload of executable files, because upload_action and edit_action i…
Jan 8, 2024
CVE-2006-3361
MEDIUM
PHP remote file inclusion vulnerability in Stud.IP 1.3.0-2 and earlier, when register_globals is enabled, allows remote…
Jul 6, 2006
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2023-50982 | Stud.IP 5.x through 5.3.3 allows XSS with resultant upload of executable files, because upload_action and edit_action in Admin_SmileysController do not check t… | CRITICAL | 1.29% | Jan 8, 2024 |
| CVE-2006-3361 | PHP remote file inclusion vulnerability in Stud.IP 1.3.0-2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code… | MEDIUM | 2.70% | Jul 6, 2006 |
Showing 1 to 2 of 2 CVEs