VendorsPluggedoutpluggedout_blogall versions
Vulnerabilities

Pluggedout Pluggedout Blog

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2006-0563
SQL injection vulnerability in exec.php in PluggedOut Blog 1.9.9c allows remote attackers to execute arbitrary SQL commands via the entryid parameter in a comment_add action.
Published 2006-02-06 · Modified
7.5EPSS 0.027
CVE-2005-4054
SQL injection vulnerability in index.php in PluggedOut Blog 1.9.5 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) categoryid, (2) entryid, (3) year, (4) month, and (5) day parameter.
Published 2005-12-07 · Modified
7.51 PoCEPSS 0.011
CVE-2006-0562
Cross-site scripting (XSS) vulnerability in problem.php in PluggedOut Blog 1.9.9c allows remote attackers to inject arbitrary web script or HTML via the data parameter.
Published 2006-02-06 · Modified
4.3EPSS 0.022