Products: 1
    Vulnerabilities: 7
    Known Exploited: 0
    1
    Critical Level Threats
    1
    High Level Threats
    5
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2007-2847

    Multiple cross-site scripting (XSS) vulnerabilities in hlstats.php in HLstats 1.35, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) authusername or (2) authpassword parameter, different vectors than CVE-2007-0840 and CVE-2007-2812.

    Last Modified: Apr 23, 2026
    Published: May 24, 2007

    CVE-2007-2812

    Cross-site scripting (XSS) vulnerability in hlstats.php in HLstats 1.35, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO or (2) the action parameter.

    Last Modified: Apr 23, 2026
    Published: May 22, 2007

    CVE-2007-0840

    Cross-site scripting (XSS) vulnerability in HLstats before 1.35 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the search class. NOTE: it is possible that this issue overlaps CVE-2006-4543.3 or CVE-2006-4454.

    Last Modified: Apr 23, 2026
    Published: Feb 08, 2007

    CVE-2006-6781

    HLstats 1.20 through 1.34 allows remote attackers to obtain sensitive information via playinfo mode, with certain values of the player and playerdata[lastName][] parameters, which reveals the path in an error message.

    Last Modified: Apr 23, 2026
    Published: Dec 28, 2006

    CVE-2006-6780

    SQL injection vulnerability in the login form in HLstats 1.20 through 1.34 allows remote attackers to execute arbitrary SQL commands via the killLimit parameter.

    Last Modified: Apr 23, 2026
    Published: Dec 28, 2006
    Items Per Page
    Hlstats Vulnerabilities & Security CVEs | CVE-DB