Show filters
29 Total Results
Displaying 11-20 of 29
Sort by:
Attacker Value
Unknown

CVE-2006-7091

Disclosure Date: March 02, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in config.php in phpht Topsites FREE 1.022b allows remote attackers to execute arbitrary PHP code via a URL in the fullpath parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2006-7026

Disclosure Date: February 23, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in sources/join.php in Aardvark Topsites PHP 4.2.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[path] parameter, a different vector than CVE-2006-2149.
0
Attacker Value
Unknown

CVE-2007-0249

Disclosure Date: January 16, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in Nwom topsites 3.0 allows remote attackers to inject arbitrary web script or HTML via the o parameter.
0
Attacker Value
Unknown

CVE-2007-0250

Disclosure Date: January 16, 2007 (last updated October 04, 2023)
index.php in Nwom topsites 3.0 allows remote attackers to obtain potentially sensitive information via a ' (quote) character in the o parameter, which forces a SQL error.
0
Attacker Value
Unknown

CVE-2006-5458

Disclosure Date: October 23, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in common.php in Hinton Design phpht Topsites allows remote attackers to execute arbitrary PHP code via a URL in the phpht_real_path parameter.
0
Attacker Value
Unknown

CVE-2006-5460

Disclosure Date: October 23, 2006 (last updated November 08, 2023)
Multiple PHP remote file inclusion vulnerabilities in Hinton Design phpht Topsites allow remote attackers to execute arbitrary PHP code via a URL in the phpht_real_path parameter to (1) index.php, (2) certain other scripts in the top-level directory, and (3) certain scripts in the admin/ directory. NOTE: CVE disputes this vulnerability because $phpht_real_path is defined before use in index.php and most other files except common.php, which is already covered by CVE-2006-5458
0
Attacker Value
Unknown

CVE-2006-3902

Disclosure Date: July 27, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in phpFaber TopSites 2.0.9 allows remote attackers to inject arbitrary web script or HTML via the i_cat parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2006-3770

Disclosure Date: July 24, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in index.php in phpFaber TopSites 2.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) i_cat or (2) method parameters.
0
Attacker Value
Unknown

CVE-2006-2544

Disclosure Date: May 23, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Xtreme Topsites 1.1, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) searchthis parameter in lostid.php and (2) id parameter in stats.php. NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2006-2543

Disclosure Date: May 23, 2006 (last updated October 04, 2023)
Xtreme Topsites 1.1 allows remote attackers to trigger MySQL errors and possibly conduct SQL injection attacks via unspecified vectors in join.php.
0