
CVE-2008-0201
https://notcve.org/view.php?id=CVE-2008-0201
10 Jan 2008 — Cross-site scripting (XSS) vulnerability in index.php in ExpressionEngine 1.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL parameter. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en index.php de ExpressionEngine 1.2.1 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección mediante el parámetro URL. • http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2008-0202
https://notcve.org/view.php?id=CVE-2008-0202
10 Jan 2008 — CRLF injection vulnerability in index.php in ExpressionEngine 1.2.1 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the URL parameter. Vulnerabilidad de inyección CRLF (se refiere a CR (retorno de carro) y LF (salto de línea)) en index.php de ExpressionEngine 1.2.1 y anteriores permite a atacantes remotos inyectar cabeceras HTTP y llevar a cabo ataques de división de respuesta HTTP a través del parámetro URL. • http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2006-0461 – PMachine ExpressionEngine 1.4.1 - HTTP Referrer HTML Injection
https://notcve.org/view.php?id=CVE-2006-0461
27 Jan 2006 — Cross-site scripting (XSS) vulnerability in core.input.php in ExpressionEngine 1.4.1 allows remote attackers to inject arbitrary web script or HTML via HTTP_REFERER (referer). • https://www.exploit-db.com/exploits/27127 •