VendorsAvaticaardvark_topsites_php5.1.2
Vulnerabilities

Avatic Aardvark Topsites PHP 5.1.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2009-2304
index.php in Aardvark Topsites PHP 5.2.0 and earlier allows remote attackers to obtain sensitive information via a nonexistent account name in the u parameter in a rate action, which reveals the installation path in an error message.
Published 2009-07-02 · Modified
5.0EPSS 0.013
CVE-2009-2303
index.php in Aardvark Topsites PHP 5.2.1 and earlier allows remote attackers to obtain sensitive information via a negative integer value for the start parameter in a search action, which reveals the installation path in an error message.
Published 2009-07-02 · Modified
5.0EPSS 0.012
CVE-2009-2302
Cross-site scripting (XSS) vulnerability in index.php in Aardvark Topsites PHP 5.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action. NOTE: it was later reported that 5.2.1 is also affected.
Published 2009-07-02 · Modified
4.31 PoCEPSS 0.017