Show filters
19 Total Results
Displaying 11-19 of 19
Sort by:
Attacker Value
Unknown
CVE-2013-4482
Disclosure Date: November 23, 2013 (last updated October 05, 2023)
Untrusted search path vulnerability in python-paste-script (aka paster) in Luci 0.26.0, when started using the initscript, allows local users to gain privileges via a Trojan horse .egg-info file in the (1) current working directory or (2) its parent directories.
0
Attacker Value
Unknown
CVE-2011-0720
Disclosure Date: February 03, 2011 (last updated October 04, 2023)
Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products, allows remote attackers to obtain administrative access, read or create arbitrary content, and change the site skin via unknown vectors.
0
Attacker Value
Unknown
CVE-2010-3852
Disclosure Date: November 06, 2010 (last updated October 04, 2023)
The default configuration of Luci 0.22.4 and earlier in Red Hat Conga uses "[INSERT SECRET HERE]" as its secret key for cookies, which makes it easier for remote attackers to bypass repoze.who authentication via a forged ticket cookie.
0
Attacker Value
Unknown
CVE-2009-2145
Disclosure Date: June 22, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in transLucid 1.75 allow remote attackers to inject arbitrary web script or HTML via the (a) NodeID and (b) action parameters to the default URI, and the (c) NodeID parameter to the default URI for the admin section; and allow remote authenticated users to inject arbitrary web script or HTML via the (d) Title (aka page name) and (e) Url fields in a (1) new or (2) modified page.
0
Attacker Value
Unknown
CVE-2006-3025
Disclosure Date: June 15, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Cal.PHP3 in Chris Lea Lucid Calendar 0.22 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2006-1635
Disclosure Date: April 06, 2006 (last updated February 22, 2025)
LucidCMS 2.0.0 RC4 allows remote attackers to obtain sensitive information via a direct request to /lucid_phplib/translator.php, which reveals the path in an error message.
0
Attacker Value
Unknown
CVE-2006-1634
Disclosure Date: April 06, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in index.php in LucidCMS 2.0.0 RC4 allows remote attackers to inject arbitrary web script or HTML via the command parameter.
0
Attacker Value
Unknown
CVE-2005-3130
Disclosure Date: October 04, 2005 (last updated February 22, 2025)
SQL injection vulnerability in lucidCMS 1.0.11 allows remote attackers to execute arbitrary SQL commands via the login field.
0
Attacker Value
Unknown
CVE-2005-3127
Disclosure Date: October 04, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in index.php in lucidCMS 1.0.11 allows remote attackers to inject arbitrary web script or HTML via the query string.
0