Show filters
51 Total Results
Displaying 11-20 of 51
Sort by:
Attacker Value
Unknown

CVE-2008-0795

Disclosure Date: February 15, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the MGFi XfaQ (com_xfaq) 1.2 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an answer action.
0
Attacker Value
Unknown

CVE-2008-0562

Disclosure Date: February 04, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the Restaurant (com_restaurant) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.
0
Attacker Value
Unknown

CVE-2008-0517

Disclosure Date: January 31, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the Darko Selesi EstateAgent (com_estateagent) 0.1 component for Mambo 4.5.x and Joomla! allows remote attackers to execute arbitrary SQL commands via the objid parameter in a contact showObject action.
0
Attacker Value
Unknown

CVE-2007-5451

Disclosure Date: October 14, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in admin.color.php in the com_colorlab (aka com_color) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.
0
Attacker Value
Unknown

CVE-2007-5410

Disclosure Date: October 12, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in admin.wmtrssreader.php in the webmaster-tips.net Flash RSS Reader (com_wmtrssreader) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.
0
Attacker Value
Unknown

CVE-2007-5363

Disclosure Date: October 11, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in admin.panoramic.php in the Panoramic Picture Viewer (com_panoramic) mambot (plugin) 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2007-5310

Disclosure Date: October 09, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in admin.wmtportfolio.php in the webmaster-tips.net wmtportfolio 1.0 (com_wmtportfolio) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
0
Attacker Value
Unknown

CVE-2007-5309

Disclosure Date: October 09, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in admin.wmtgallery.php in the webmaster-tips.net Flash Image Gallery (com_wmtgallery) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.
0
Attacker Value
Unknown

CVE-2007-4185

Disclosure Date: August 08, 2007 (last updated October 04, 2023)
Joomla! 1.0.12 allows remote attackers to obtain sensitive information via a direct request for (1) Stat.php (2) OutputFilter.php, (3) OutputCache.php, (4) Modifier.php, (5) Reader.php, and (6) TemplateCache.php in includes/patTemplate/patTemplate/; (7) includes/Cache/Lite/Output.php; and other unspecified components, which reveal the path in various error messages.
0
Attacker Value
Unknown

CVE-2007-4184

Disclosure Date: August 08, 2007 (last updated October 04, 2023)
SQL injection vulnerability in administrator/popups/pollwindow.php in Joomla! 1.0.12 allows remote attackers to execute arbitrary SQL commands via the pollid parameter.
0