VendorsAJ Squareaj_articleall versions
Vulnerabilities

AJ Square Aj Article

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2008-7051
AJ Square AJ Article allows remote attackers to bypass authentication and access administrator functionality via a direct request to (1) user.php, (2) articles.php, (3) articlesuspend.php, (4) site.php, (5) statistics.php, (6) mail.php, (7) category.php, (8) subcategory.php, (9) changepassword.php, (10) polling.php, and (11) logo.php in admin/.
Published 2009-08-24 · Modified
7.51 PoCEPSS 0.025
CVE-2008-6721
SQL injection vulnerability in index.php in AJ Square AJ Article allows remote attackers to execute arbitrary SQL commands via the txtName parameter (aka the username field).
Published 2009-04-14 · Modified
7.51 PoCEPSS 0.010
CVE-2010-2917
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AJ Square AJ Article 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) emailid, (2) fname, (3) lname, (4) company, (5) address1, (6) address2, (7) city, (8) state, (9) zipcode, (10) phone, and (11) fax parameters in an update action. NOTE: some of these details are obtained from third party information.
Published 2010-07-30 · Modified
4.31 PoCEPSS 0.017