Leif M. Wright

    Dashboard / Vendors

    Products: 5
    Vulnerabilities: 13
    Known Exploited: 0
    4
    Critical Level Threats
    3
    High Level Threats
    6
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2006-0846

    Multiple cross-site scripting (XSS) vulnerabilities in Leif M. Wright's Blog 3.5 allow remote attackers to inject arbitrary web script or HTML via the (1) Referer and (2) User-Agent HTTP headers, which are stored in a log file and not sanitized when the administrator views the "Log" page, possibly using the ViewCommentsLog function.

    Last Modified: Apr 16, 2026
    Published: Feb 22, 2006

    CVE-2006-0844

    Leif M. Wright's Blog 3.5 does not make a password comparison when authenticating an administrator via a cookie, which allows remote attackers to bypass login authentication, probably by setting the blogAdmin cookie.

    Last Modified: Apr 16, 2026
    Published: Feb 22, 2006

    CVE-2006-0843

    Leif M. Wright's Blog 3.5 stores the config file and other txt files under the web root with insufficient access control, which allows remote attackers to read the administrator's password.

    Last Modified: Apr 16, 2026
    Published: Feb 22, 2006

    CVE-2006-0845

    Leif M. Wright's Blog 3.5 allows remote authenticated users with administrative privileges to execute arbitrary programs, including shell commands, by configuring the sendmail path to a malicious pathname.

    Last Modified: Apr 16, 2026
    Published: Feb 22, 2006

    CVE-2005-1350

    The ad.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.

    Last Modified: Apr 16, 2026
    Published: Apr 28, 2005
    Items Per Page