Geeklog Project maintains a niche content management system product, with observed vulnerabilities concentrating on web-application input-handling issues, particularly cross-site scripting weaknesses that arise in page generation and rendering. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Geeklog Project over time
Signals from CVEs in this vendor scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-2793HIGH PHP remote file inclusion vulnerability in ImageImageMagick.php in Geeklog 2.x allows remote attackers to execute arbitrary PHP code via a URL in the glConf[path_system] parameter. | May 22, 2007 | 7.5 | 64 | NO | YES |
CVE-2002-0962HIGH Cross-site scripting vulnerabilities in GeekLog 1.3.5 and earlier allow remote attackers to execute arbitrary script via (1) the url variable in the Link field of a calendar event, | Oct 4, 2002 | 7.5 | 32 | NO | YES |
CVE-2010-4933HIGH SQL injection vulnerability in filemgmt/singlefile.php in Geeklog 1.3.8 allows remote attackers to execute arbitrary SQL commands via the lid parameter. | Oct 9, 2011 | 7.5 | 30 | NO | YES |
CVE-2007-0810HIGH PHP remote file inclusion vulnerability in MVCnPHP/BaseView.php in GeekLog 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the glConf[path_librarie | Feb 7, 2007 | 7.5 | 30 | NO | YES |
CVE-2007-2706HIGH PHP remote file inclusion vulnerability in maint/ftpmedia.php in Media Gallery 1.4.8a and earlier for Geeklog allows remote attackers to execute arbitrary PHP code via a URL in the | May 16, 2007 | 7.5 | 29 | NO | YES |
CVE-2006-0823HIGH Multiple SQL injection vulnerabilities in Geeklog 1.4.0 before 1.4.0sr1 and 1.3.11 before 1.3.11sr4 allow remote attackers to inject arbitrary SQL commands via the (1) userid varia | Feb 21, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-2699MEDIUM Cross-site scripting (XSS) vulnerability in getimage.php in Geeklog 1.4.0sr2 and earlier allows remote attackers to inject arbitrary HTML or web script via the image argument in a | May 31, 2006 | 6.8 | 27 | NO | YES |
CVE-2006-1069HIGH Unspecified vulnerability in the session handling for Geeklog 1.4.x before 1.4.0sr2, 1.3.11 before 1.3.11sr5, 1.3.9 before 1.3.9sr5, and possibly earlier versions allows attackers | Mar 7, 2006 | 10.0 | 25 | NO | NO |
CVE-2006-6225MEDIUM Multiple PHP remote file inclusion vulnerabilities in GeekLog 1.4 allow remote attackers to execute arbitrary code via a URL in the _CONF[path] parameter to (1) links/functions.inc | Dec 2, 2006 | 5.1 | 24 | NO | YES |
CVE-2006-3362MEDIUM Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) Geeklog 1.4.0 through 1.4.0sr3, (2) toendaCMS 1.0.0 Shizouka | Jul 6, 2006 | 5.1 | 24 | NO | YES |
Signals from CVEs in this vendor scope (33 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Geeklog Project.
Media articles that mention a CVE ID that affects a product developed by Geeklog Project — matched by CVE ID, not by vendor name.