CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
statusnet through 2010 allows attackers to spoof syslog messages via newline injection attacks. |
Cross-site scripting (XSS) vulnerability in statusnet through 2010 in error message contents. |
Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes.. |
statusnet before 0.9.9 has XSS |
Multiple SQL injection vulnerabilities in StatusNet 1.0 before 1.0.2 and 1.1.0 allow remote attackers to execute arbitrary SQL commands via vectors related to user lists and "a particular tag format." |
StatusNet 0.9.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tpl/index.php and certain other fil...Show more |