Show filters
19 Total Results
Displaying 11-19 of 19
Sort by:
Attacker Value
Unknown

CVE-2013-4482

Disclosure Date: November 23, 2013 (last updated October 05, 2023)
Untrusted search path vulnerability in python-paste-script (aka paster) in Luci 0.26.0, when started using the initscript, allows local users to gain privileges via a Trojan horse .egg-info file in the (1) current working directory or (2) its parent directories.
0
Attacker Value
Unknown

CVE-2011-0720

Disclosure Date: February 03, 2011 (last updated October 04, 2023)
Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products, allows remote attackers to obtain administrative access, read or create arbitrary content, and change the site skin via unknown vectors.
0
Attacker Value
Unknown

CVE-2010-3852

Disclosure Date: November 06, 2010 (last updated October 04, 2023)
The default configuration of Luci 0.22.4 and earlier in Red Hat Conga uses "[INSERT SECRET HERE]" as its secret key for cookies, which makes it easier for remote attackers to bypass repoze.who authentication via a forged ticket cookie.
0
Attacker Value
Unknown

CVE-2009-2145

Disclosure Date: June 22, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in transLucid 1.75 allow remote attackers to inject arbitrary web script or HTML via the (a) NodeID and (b) action parameters to the default URI, and the (c) NodeID parameter to the default URI for the admin section; and allow remote authenticated users to inject arbitrary web script or HTML via the (d) Title (aka page name) and (e) Url fields in a (1) new or (2) modified page.
0
Attacker Value
Unknown

CVE-2006-3025

Disclosure Date: June 15, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Cal.PHP3 in Chris Lea Lucid Calendar 0.22 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2006-1635

Disclosure Date: April 06, 2006 (last updated February 22, 2025)
LucidCMS 2.0.0 RC4 allows remote attackers to obtain sensitive information via a direct request to /lucid_phplib/translator.php, which reveals the path in an error message.
0
Attacker Value
Unknown

CVE-2006-1634

Disclosure Date: April 06, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in index.php in LucidCMS 2.0.0 RC4 allows remote attackers to inject arbitrary web script or HTML via the command parameter.
0
Attacker Value
Unknown

CVE-2005-3130

Disclosure Date: October 04, 2005 (last updated February 22, 2025)
SQL injection vulnerability in lucidCMS 1.0.11 allows remote attackers to execute arbitrary SQL commands via the login field.
0
Attacker Value
Unknown

CVE-2005-3127

Disclosure Date: October 04, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in index.php in lucidCMS 1.0.11 allows remote attackers to inject arbitrary web script or HTML via the query string.
0