dynpg dynpg CVE Vulnerabilities (11)

CVEs: 11 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting dynpg dynpg (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 111 of 11 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2020-27406 Cross Site Scripting (XSS) vulnerability in DynPG 4.9.1, allows authenticated attackers to execute arbitrary code via the groupname. [email protected] 5.4 0.38% 2021-11-02 2024-11-21
CVE-2021-27531 A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "query" parameter. [email protected] 4.8 0.18% 2021-03-23 2024-11-21
CVE-2021-27530 A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allow remote attacker to inject javascript via URI in /index.php. [email protected] 4.8 0.18% 2021-03-23 2024-11-21
CVE-2021-27529 A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "limit" parameter. [email protected] 4.8 0.16% 2021-03-23 2024-11-21
CVE-2021-27528 A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "refID" parameter. [email protected] 4.8 0.18% 2021-03-23 2024-11-21
CVE-2021-27527 A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "valueID" parameter. [email protected] 4.8 0.16% 2021-03-23 2024-11-21
CVE-2021-27526 A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "page" parameter. [email protected] 4.8 0.18% 2021-03-23 2024-11-21
CVE-2010-4401 languages.inc.php in DynPG CMS 4.2.0 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message. [email protected] 5.0 4.38% 2010-12-06 2026-04-29
CVE-2010-4400 SQL injection vulnerability in _rights.php in DynPG CMS 4.2.0 allows remote attackers to execute arbitrary SQL commands via the giveRights_UserId parameter. [email protected] 7.5 0.56% 2010-12-06 2026-04-29
CVE-2010-4399 Directory traversal vulnerability in languages.inc.php in DynPG CMS 4.1.1 and 4.2.0, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the CHG_DYNPG_SET_LANGUAGE parameter to index.php. NOTE: some of these details are obtained from third party information. [email protected] 4.3 7.06% 2010-12-06 2026-04-29
CVE-2010-1299 Multiple PHP remote file inclusion vulnerabilities in DynPG CMS 4.1.0, and possibly earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) DefineRootToTool parameter to counter.php, (2) PathToRoot parameter to plugins/DPGguestbook/guestbookaction.php and (3) get_popUpResource parameter to backendpopup/popup.php. NOTE: some of these details are obtained from third party information. [email protected] 5.1 11.24% 2010-04-07 2026-04-29
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence