Show filters
36 Total Results
Displaying 11-20 of 36
Sort by:
Attacker Value
Unknown

CVE-2012-5228

Disclosure Date: October 01, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in admin/index.php in phplist 2.10.9, 2.10.17, and possibly other versions before 2.10.19 allows remote attackers to inject arbitrary web script or HTML via the testtarget parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2010-4814

Disclosure Date: July 08, 2011 (last updated October 04, 2023)
SQL injection vulnerability in index1.php in Best Soft Inc. (BSI) Advance Hotel Booking System 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.
0
Attacker Value
Unknown

CVE-2011-1682

Disclosure Date: April 13, 2011 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in phpList 2.10.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) create a list or (2) insert cross-site scripting (XSS) sequences. NOTE: this issue exists because of an incomplete fix for CVE-2011-0748. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2011-0748

Disclosure Date: April 13, 2011 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in phpList before 2.10.13 allow remote attackers to hijack the authentication of administrators for requests that (1) add or (2) edit administrator accounts.
0
Attacker Value
Unknown

CVE-2010-4311

Disclosure Date: November 26, 2010 (last updated October 04, 2023)
Free Simple Software 1.0 stores passwords in cleartext, which allows context-dependent attackers to obtain sensitive information.
0
Attacker Value
Unknown

CVE-2010-4298

Disclosure Date: November 26, 2010 (last updated October 04, 2023)
SQL injection vulnerability in the download module in Free Simple Software 1.0 allows remote attackers to execute arbitrary SQL commands via the downloads_id parameter in a download_now action to index.php.
0
Attacker Value
Unknown

CVE-2010-3742

Disclosure Date: October 05, 2010 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Free Simple CMS 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) meta or (2) phpincdir parameter, a different issue than CVE-2010-3307.
0
Attacker Value
Unknown

CVE-2010-3307

Disclosure Date: October 05, 2010 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Free Simple CMS 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) body, (2) footer, (3) header, (4) menu_left, or (5) menu_right parameter.
0
Attacker Value
Unknown

CVE-2008-6811

Disclosure Date: May 18, 2009 (last updated October 04, 2023)
Unrestricted file upload vulnerability in image_processing.php in the e-Commerce Plugin 3.4 and earlier for Wordpress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/plugins/wp-shopping-cart/.
0
Attacker Value
Unknown

CVE-2009-0422

Disclosure Date: February 05, 2009 (last updated October 04, 2023)
Dynamic variable evaluation vulnerability in lists/admin.php in phpList 2.10.8 and earlier, when register_globals is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the _SERVER[ConfigFile] parameter to admin/index.php.
0