VendorsSpoonlabsvivvo_article_management_cmsall versions
Vulnerabilities

Spoonlabs Vivvo Article Management CMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2006-4715
SQL injection vulnerability in pdf_version.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
Published 2006-09-12 · Modified
7.52 PoCEPSS 0.026
CVE-2007-0574
SQL injection vulnerability in rss/show_webfeed.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.40 allows remote attackers to execute arbitrary SQL commands via the wcHeadlines parameter, a different vector than CVE-2006-4715. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
Published 2007-01-30 · Modified
7.51 PoCEPSS 0.020
CVE-2007-3939
SQL injection vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) CMS 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter.
Published 2007-07-21 · Modified
6.82 PoCEPSS 0.021
CVE-2007-1031
Directory traversal vulnerability in include/db_conn.php in SpoonLabs Vivvo Article Management CMS 3.4 allows remote attackers to include and execute arbitrary local files via the root parameter.
Published 2007-02-21 · Modified
6.81 PoCEPSS 0.020
CVE-2006-4714
PHP remote file inclusion vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the classified_path parameter.
Published 2006-09-12 · Modified
5.12 PoCEPSS 0.034