MidnightBSD

Advisories for clantiger

CVE-2010-1863 HIGH

SQL injection vulnerability in the shoutbox module (modules/shoutbox.php) in ClanTiger 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the s_email parameter.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
clantiger clantiger 1.1
clantiger clantiger 0.2
clantiger clantiger 1.0
clantiger clantiger *
clantiger clantiger 1.1.2
clantiger clantiger 1.1.1
CVE-2011-3715 MEDIUM

ClanTiger 1.1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by widgets/statistics/statistics.php and certain other files.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
clantiger clantiger 1.1.3