Vulnerabilities (CVE)

Filtered by vendor Wowroster Subscribe
Filtered by product Wowroster
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-3998 1 Wowroster 1 Wowroster 2024-02-04 7.5 HIGH N/A
PHP remote file inclusion vulnerability in conf.php in WoWRoster (aka World of Warcraft Roster) 1.5.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the subdir parameter.
CVE-2006-3997 1 Wowroster 1 Wowroster 2024-02-04 7.5 HIGH N/A
PHP remote file inclusion vulnerability in hsList.php in WoWRoster (aka World of Warcraft Roster) 1.5.x and earlier allows remote attackers to execute arbitrary PHP code via a URL in the subdir parameter.