bloo CVE Vulnerabilities & CVE List (3)

Products (CPE): — CVEs: 3

bloo vulnerability overview

Aggregates CVE and security vulnerability intelligence across all bloo-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk path handling and vendor risk cross-site scripting and related problems; some flaws may lead to vendor impact file overwrite, affecting vendor surface production workloads scenarios.

Vulnerability distribution trend (last 24 months)

Showing 13 of 3 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2008-0427 Directory traversal vulnerability in file.php in bloofoxCMS 0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. [email protected] 7.8 15.69% 2008-01-23 2026-04-23
CVE-2006-6023 PHP remote file inclusion vulnerability in phoo.base.php in Bill Roberts Bloo 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the descriptorFileList parameter. NOTE: this issue is disputed by CVE since $descriptorFileList is used in a function definition within phoo.base.php [email protected] 7.5 1.40% 2006-11-21 2026-04-23
CVE-2006-6019 Cross-site scripting (XSS) vulnerability in extensions/googiespell/googlespell_proxy.php in Bill Roberts Bloo 1.0 allows remote attackers to inject arbitrary web script or HTML via the lang parameter. [email protected] 6.8 1.21% 2006-11-21 2026-04-23
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence