VendorsJoomla!bsq_sitestats2.1.1
Vulnerabilities

Joomla! Bsq Sitestats 2.1.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2006-4995
PHP remote file inclusion vulnerability in BSQ Sitestats (bsq_sitestats) before 2.1.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
Published 2006-09-26 · Modified
7.5EPSS 0.018
CVE-2006-7125
Cross-site scripting (XSS) vulnerability in Joomla BSQ Sitestats 1.8.0 and 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header, which is not properly handled when the administrator views site statistics.
Published 2007-03-06 · Modified
6.8EPSS 0.012
CVE-2006-7126
SQL injection vulnerability in Joomla BSQ Sitestats 1.8.0 and 2.2.1 allows remote attackers to execute arbitrary SQL commands via the query string, possibly PHP_SELF.
Published 2007-03-06 · Modified
6.8EPSS 0.012