📦

weblog

Vendor: archangelmgt

Actively Exploited 0 CISA KEV List
PoC / Exploits 5 Code Available
Total RCEs 2 Remote Access
Total CVEs 4 Total Indexed
Avg. EPSS 4.26% Exploit Prob.
Latest CVE CVE-2016-4504 Mar 21

Security Vulnerability Index

Page 1 / 1
8.8 CVSS

A Cross-Site Request Forgery issue was discovered in Meteocontrol WEB'log Basic 100 all versions, Light all versions, Pro all versions, and Pro Unlimited all versions. There is no CSRF Token generated per page or per function.

EPSS: 0.10%
7.5 CVSS
CVE-2008-3318
Exploit Found

admin/index.php in Maian Weblog 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary weblog_cookie cookie.

EPSS: 8.94%
7.5 CVSS
CVE-2008-0442
RCE Exploit Found

PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the ffile parameter, a different vector than CVE-2008-0376. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: 1.74%
5.0 CVSS
CVE-2007-2574
Exploit Found

Directory traversal vulnerability in index.php in Archangel Weblog 0.90.02 allows remote attackers to read arbitrary files via a .. (dot dot) in the index parameter.

EPSS: 5.38%
6.8 CVSS

PHP remote file inclusion vulnerability in index.php in Maian Weblog 3.1 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter. NOTE: this issue was disputed by a third party researcher, since the path_to_folder variable is initialized before use

EPSS: 2.40%
5.0 CVSS
CVE-2007-1487
Exploit Found

Directory traversal vulnerability in index.php in Sascha Schroeder (aka CyberTeddy or Cyber-inside) WebLog allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter in a showarticles action.

EPSS: 12.12%
4.3 CVSS

Multiple cross-site scripting (XSS) vulnerabilities in Archangel Management Archangel Weblog 0.90.02 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Comment section.

EPSS: 0.43%
7.5 CVSS
CVE-2006-0944
Exploit Found

Archangel Weblog 0.90.02 allows remote attackers to bypass authentication by setting the ba_admin cookie to 1.

EPSS: 6.25%
6.5 CVSS

PHP remote file include vulnerability in admin/index.php in Archangel Weblog 0.90.02 allows remote authenticated administrators to execute arbitrary PHP code via a URL ending in a NULL (%00) in the index parameter.

EPSS: 0.97%