VendorsRicardo Alexandre De Oliveira Staudtyogurt0.3
Vulnerabilities

Ricardo Alexandre De Oliveira Staudt Yogurt 0.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2009-2034
SQL injection vulnerability in writemessage.php in Yogurt 0.3, when register_globals is enabled, allows remote authenticated users to execute arbitrary SQL commands via the original parameter.
Published 2009-06-12 · Modified
6.01 PoCEPSS 0.008
CVE-2009-2033
Cross-site scripting (XSS) vulnerability in index.php in Yogurt 0.3 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
Published 2009-06-12 · Modified
4.31 PoCEPSS 0.015