Vendorsbananadancebanana_danceall versions
Vulnerabilities

bananadance Banana Dance

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2012-5244
Multiple SQL injection vulnerabilities in Banana Dance B.2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) return, (2) display, (3) table, or (4) search parameter to functions/suggest.php; (5) the id parameter to functions/widgets.php, (6) the category parameter to functions/print.php; or (7) the name parameter to functions/ajax.php.
Published 2014-10-20 · Modified
7.51 PoCEPSS 0.015
CVE-2011-5175
SQL injection vulnerability in search.php in Banana Dance, possibly B.1.5 and earlier, allows remote attackers to execute arbitrary SQL commands via the category parameter.
Published 2012-09-15 · Modified
7.5EPSS 0.013
CVE-2011-5168
SQL injection vulnerability in user.php in Banana Dance before B.1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Published 2012-09-15 · Modified
7.51 PoCEPSS 0.013
CVE-2012-5242
Directory traversal vulnerability in functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter in a get_template action.
Published 2014-10-21 · Modified
6.81 PoCEPSS 0.025
CVE-2012-5243
functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to read arbitrary database information via a crafted request.
Published 2014-10-21 · Modified
5.01 PoCEPSS 0.028
CVE-2011-5176
Multiple cross-site scripting (XSS) vulnerabilities in search.php in Banana Dance, possibly B.1.5 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) q or (2) category parameter.
Published 2012-09-15 · Modified
4.3EPSS 0.009