Vulnerabilities
9 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-47915 | PHP Melody version 3.0 contains a remote SQL injection vulnerability in the video edit module that allows authenticated attackers to inject malicious SQL comman PHP Melody version 3.0 contains a remote SQL injection vulnerability in the video edit module that allows authenticated attackers to inject malicious SQL commands. Attackers can exploit the unvalidated 'vid' parameter to execute arbitrary database queries and potentially compromise the web application and database management system. NVD description · AI analysis pending | 8.6 group max | <1% | PoC |
| — | |
| CVE-2018-5211 | PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist. PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2017-15081 | In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php. In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php. NVD description · AI analysis pending | 9.8 | 2% | PoC ×3 |
| — | |
| CVE-2017-15648 | In PHPSUGAR PHP Melody before 2.7.3, page_manager.php has XSS via the page_title parameter. In PHPSUGAR PHP Melody before 2.7.3, page_manager.php has XSS via the page_title parameter. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2017-15579 +1 in the same advisory: …15578 | In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via an aa_pages_per_page cookie in a playlist action to watch.php. In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via an aa_pages_per_page cookie in a playlist action to watch.php. NVD description · AI analysis pending | 9.8 group max | 1% | PoC |
| — |