This CPE summary could be partial or incomplete. Please contact us for a detailed listing.
Summary
Detail | |||
---|---|---|---|
Vendor | Imgurl Project | First view | 2021-08-16 |
Product | Imgurl | Last view | 2022-05-24 |
Version | 2.31 | Type | Application |
Update | * | ||
Edition | * | ||
Language | * | ||
Sofware Edition | * | ||
Target Software | * | ||
Target Hardware | * | ||
Other | * | ||
CPE Product | cpe:2.3:a:imgurl_project:imgurl |
Activity : Overall
Related : CVE
Date | Alert | Description | |
---|---|---|---|
8.1 | 2022-05-24 | CVE-2022-29305 | imgurl v2.31 was discovered to contain a Blind SQL injection vulnerability via /upload/localhost. |
5.4 | 2021-08-16 | CVE-2021-38713 | imgURL 2.31 allows XSS via an X-Forwarded-For HTTP header. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
50% (1) | CWE-89 | Improper Sanitization of Special Elements used in an SQL Command ('... |
50% (1) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |