VendorsAlexander Palmosimple_php_blog0.4.0
Vulnerabilities

Alexander Palmo Simple PHP Blog 0.4.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2005-2733
upload_img_cgi.php in Simple PHP Blog (SPHPBlog) does not properly restrict file extensions of uploaded files, which could allow remote attackers to execute arbitrary code.
Published 2005-08-29 · Modified
7.52 PoCEPSS 0.512
CVE-2006-1243
Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the blog_language parameter, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included using install05.php.
Published 2006-03-15 · Modified
7.51 PoCEPSS 0.097
CVE-2009-4421
Directory traversal vulnerability in languages_cgi.php in Simple PHP Blog 0.5.1 and earlier allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the blog_language1 parameter.
Published 2009-12-24 · Modified
6.51 PoCEPSS 0.020
CVE-2005-2787
comment_delete_cgi.php in Simple PHP Blog allows remote attackers to delete arbitrary files via the comment parameter.
Published 2005-09-02 · Modified
5.01 PoCEPSS 0.056
CVE-2005-2192
SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote attackers to obtain passwords via a brute force attack.
Published 2005-07-10 · Modified
5.01 PoCEPSS 0.041
CVE-2005-1137
Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to obtain sensitive information via a direct request to sb_functions.php, which leaks the full pathname in a PHP error message.
Published 2005-04-16 · Modified
5.0EPSS 0.013
CVE-2005-1135
Cross-site scripting (XSS) vulnerability in search.php for Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.
Published 2005-04-16 · Modified
4.31 PoCEPSS 0.017