VendorsKatalog.hurricanekatalog_stron_hurricane1.3.5
Vulnerabilities

Katalog.hurricane Katalog Stron Hurricane 1.3.5

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2010-0677
SQL injection vulnerability in index.php in Katalog Stron Hurricane 1.3.5, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the get parameter.
Published 2010-02-22 · Modified
7.51 PoCEPSS 0.010
CVE-2010-0678
PHP remote file inclusion vulnerability in includes/moderation.php in Katalog Stron Hurricane 1.3.5, and possibly earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the includes_directory parameter.
Published 2010-02-22 · Modified
6.81 PoCEPSS 0.018