Filtered by vendor Yap Subscriptions
Filtered by product Yap Blog Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2009-1038 1 Yap 1 Yap Blog 2024-11-21 N/A
Multiple SQL injection vulnerabilities in YAP Blog 1.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) image_id parameter to comments.php, and remote authenticated administrators to execute arbitrary SQL commands via the (2) user parameter in a modif action to admin/index.php.