Vulnerabilities (CVE)

Filtered by vendor Codologic Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-9261 1 Codologic 1 Codoforum 2020-02-18 5.0 MEDIUM N/A
The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to index.php.
CVE-2013-5952 2 Codologic, Joomla 2 Com Freichat, Joomla\! 2017-08-29 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in the Freichat (com_freichat) component, possibly 9.4 and earlier, for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) id or (2) xhash parameter to client/chat.php or (3) toname parameter to client/plugins/upload/upload.php.