← Back

Karl Core

karl_core

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Bandsite Cms
bandsite_cms

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Karl Core
1Bandsite Cms
Apr 29, 2026
Apr 22, 2010
N/A· v4
N/A· v3
6.0 MEDIUM· v2
Unrestricted file upload vulnerability in adminpanel/scripts/addphotos.php in BandSite CMS 1.1.4 allows remote authenticated administrators to execute arbitrary PHP code by uploading a file with an executable extension v...Show more
Unrestricted file upload vulnerability in adminpanel/scripts/addphotos.php in BandSite CMS 1.1.4 allows remote authenticated administrators to execute arbitrary PHP code by uploading a file with an executable extension via an addphotos action to adminpanel/index.php, and then accessing the file via a direct request with an images/gallery/ directory name. NOTE: some of these details are obtained from third party information.Show less
1Karl Core
1Bandsite Cms
Apr 29, 2026
Apr 22, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in includes/content/member_content.php in BandSite CMS 1.1.4 allows remote attackers to execute arbitrary SQL commands via the memid parameter to members.php.