Vulnerabilities (CVE)

Filtered by vendor Squiz Subscribe
Filtered by product Mysource Classic
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-5036 1 Squiz 2 Mysource Classic, Mysource Matrix 2024-04-11 6.8 MEDIUM N/A
MySource Matrix 3.8 and earlier, and MySource 2.x, allow remote attackers to use the application as an HTTP proxy server via the sq_remote_page_url parameter to access arbitrary sites with the server's IP address and conduct cross-site scripting (XSS) attacks. NOTE: the researcher reports that "The vendor does not consider this a vulnerability.
CVE-2006-4635 1 Squiz 1 Mysource Classic 2023-12-10 6.5 MEDIUM N/A
Unspecified vulnerability in MySource Classic 2.14.6, and possibly earlier, allows remote authenticated users, with superuser privileges, to inject arbitrary PHP code via unspecified vectors related to the Equation attribute in Web_Extensions - Notitia (I/II). NOTE: due to lack of details, it is not clear whether this issue is file inclusion, static code injection, or another type of issue.