VendorsGrayscalegrayscale_blogall versions
Vulnerabilities

Grayscale Grayscale Blog

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2007-1432
Grayscale Blog 0.8.0, and possibly earlier versions, allows remote attackers to gain privileges via direct requests with modified arguments in (1) the user_permissions parameter to add_users.php, and unspecified parameters to (2) addblog.php, (3) editblog.php, (4) editlinks.php, (5) edit_users.php, and (6) add_links.php.
Published 2007-03-13 · Modified
7.51 PoCEPSS 0.023
CVE-2007-1434
SQL injection vulnerability in Grayscale Blog 0.8.0, and possibly earlier versions, might allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) userdetail.php, id and (2) url parameter to (b) jump.php, and id variable to (c) detail.php.
Published 2007-03-13 · Modified
7.51 PoCEPSS 0.010
CVE-2007-1433
Cross-site scripting (XSS) vulnerability in Grayscale Blog 0.8.0, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the comment fields to (1) scripts/addblog_comment.php and (2) detail.php.
Published 2007-03-13 · Modified
4.31 PoCEPSS 0.015