Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Lifetype MEDIUM 5.0
CVE-2011-3751

LifeType 1.2.10 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in a…

No fix yet
Fix from $1,600 2011-09-23
Lifetype HIGH 7.5
CVE-2008-2629

SQL injection vulnerability in the LifeType (formerly pLog) module for Drupal allows remote attackers to execute arbitrary SQL commands via the album…

No fix yet
Fix from $1,950 2008-06-10
Lifetype MEDIUM 5.0
CVE-2007-0979

Unspecified vulnerability in LifeType before 1.1.6, and 1.2 before 1.2-beta2, allows remote attackers to obtain sensitive information (file contents)…

Fix: after 1.2_beta_1
Fix from $1,600 2007-02-16
Lifetype MEDIUM 5.0
CVE-2006-6112

LifeType 1.0.x and 1.1.x have insufficient access control for all of the PHP scripts under (1) class/ and (2) plugins/, which allows remote attackers…

Patch available
Fix from $1,600 2006-12-06
Lifetype HIGH 7.5
CVE-2006-3577

SQL injection vulnerability in index.php in LifeType 1.0.5 allows remote attackers to execute arbitrary SQL commands via the Date parameter in a Defa…

Patch available
Fix from $1,950 2006-07-13
Lifetype HIGH 7.5
CVE-2006-2857

SQL injection vulnerability in index.php in LifeType 1.0.4 allows remote attackers to execute arbitrary SQL commands via the articleId parameter in a…

Patch available
Fix from $1,950 2006-06-06
Lifetype MEDIUM 5.0
CVE-2006-1809

index.php in Lifetype 1.0.3 allows remote attackers to obtain sensitive information via an invalid show parameter, which reveals the path in an error…

Mitigation only
Fix from $1,600 2006-04-18