Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown
CVE-2004-2322
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
SQL injection vulnerability in the (1) announce and (2) notes modules of phpWebSite before 0.9.3-2 allows remote attackers to execute arbitrary SQL queries, as demonstrated using the ANN_id parameter to the announce module.
0
Attacker Value
Unknown
CVE-2004-1654
Disclosure Date: September 01, 2004 (last updated February 22, 2025)
SQL injection vulnerability in the calendar module in phpWebsite 0.9.3-4 and earlier allows remote attackers to execute arbitrary SQL commands via cal_template.
0
Attacker Value
Unknown
CVE-2004-1655
Disclosure Date: September 01, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in phpWebsite 0.9.3-4 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) CM_pid parameter in the comments module or (2) the subject or message fields in the notes module.
0
Attacker Value
Unknown
CVE-2003-0736
Disclosure Date: October 20, 2003 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute arbitrary web script via (1) the day parameter in the calendar module, (2) the fatcat_id parameter in the fatcat module, (3) the PAGE_id parameter in the pagemaster module, (4) the PDA_limit parameter in the search, and (5) possibly other parameters in the calendar, fatcat, and pagemaster modules.
0
Attacker Value
Unknown
CVE-2003-0735
Disclosure Date: October 20, 2003 (last updated February 22, 2025)
SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and earlier allows remote attackers to execute arbitrary SQL queries, as demonstrated using the year parameter.
0
Attacker Value
Unknown
CVE-2003-0737
Disclosure Date: October 20, 2003 (last updated February 22, 2025)
The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to obtain the full pathname of phpWebSite via an invalid year, which generates an error from localtime() in TimeZone.php of the Pear library.
0
Attacker Value
Unknown
CVE-2003-0738
Disclosure Date: October 20, 2003 (last updated February 22, 2025)
The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to cause a denial of service (crash) via a long year parameter.
0
Attacker Value
Unknown
CVE-2002-1807
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in phpWebSite 0.8.3 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.
0
Attacker Value
Unknown
CVE-2002-2178
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in article.php module for phpWebSite 0.8.3 allows remote attackers to execute arbitrary Javascript script via the sid parameter, as demonstrated using an IMG tag.
0
Attacker Value
Unknown
CVE-2002-1135
Disclosure Date: October 04, 2002 (last updated February 22, 2025)
modsecurity.php 1.10 and earlier, in phpWebSite 0.8.2 and earlier, allows remote attackers to execute arbitrary PHP source code via an inc_prefix parameter that points to the malicious code.
0