Vulnerabilities (CVE)

Filtered by vendor Chxo Subscribe
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-4552 1 Chxo 1 Feedsplitter 2024-02-04 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in CHXO Feedsplitter 2006-01-21 allows remote attackers to inject arbitrary web script or HTML via the RSS feed.
CVE-2006-4550 1 Chxo 1 Feedsplitter 2024-02-04 5.0 MEDIUM N/A
Directory traversal vulnerability in CHXO Feedsplitter 2006-01-21 allows remote attackers to read arbitrary XML files via .. (dot dot) sequences in the format parameter with a leading ".", which bypasses a security check.
CVE-2006-4549 1 Chxo 1 Feedsplitter 2024-02-04 5.0 MEDIUM N/A
CHXO Feedsplitter 2006-01-21 allows remote attackers to read the source code of feedsplitter.php via the showsource function. NOTE: this issue is not a vulnerability in standard distributions, but could be an issue if the source has been modified.
CVE-2006-4551 1 Chxo 1 Feedsplitter 2024-02-04 7.5 HIGH N/A
Eval injection vulnerability in CHXO Feedsplitter 2006-01-21 allows remote attackers to execute arbitrary PHP code via (1) the file specified as the value of the format parameter, and possibly (2) the RSS feed.