Show filters
98 Total Results
Displaying 11-20 of 98
Sort by:
Attacker Value
Unknown
CVE-2014-3935
Disclosure Date: June 02, 2014 (last updated October 05, 2023)
SQL injection vulnerability in glossaire-aff.php in the Glossaire module 1.0 for XOOPS allows remote attackers to execute arbitrary SQL commands via the lettre parameter.
0
Attacker Value
Unknown
CVE-2011-4565
Disclosure Date: November 28, 2011 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.5.1.a, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to include/formdhtmltextarea_preview.php or (2) img BBCODE tag within the message parameter to pmlite.php (aka Private Message). NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2011-3822
Disclosure Date: September 24, 2011 (last updated October 04, 2023)
XOOPS 2.5.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/system/xoops_version.php and certain other files.
0
Attacker Value
Unknown
CVE-2009-4851
Disclosure Date: May 07, 2010 (last updated October 04, 2023)
The activation resend function in the Profiles module in XOOPS before 2.4.1 sends activation codes in response to arbitrary activation requests, which allows remote attackers to bypass administrative approval via a request involving activate.php.
0
Attacker Value
Unknown
CVE-2009-4582
Disclosure Date: January 06, 2010 (last updated October 04, 2023)
SQL injection vulnerability in detail.php in the Dictionary module for XOOPS 2.0.18 allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown
CVE-2009-3963
Disclosure Date: November 17, 2009 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in XOOPS before 2.4.0 Final have unknown impact and attack vectors.
0
Attacker Value
Unknown
CVE-2008-7178
Disclosure Date: September 08, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a downloadfile action to index.php.
0
Attacker Value
Unknown
CVE-2008-7036
Disclosure Date: August 24, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in index.php in DevTracker module 3.0 for bcoos 1.1.11 and earlier, and DevTracker module 0.20 for E-XooPS 1.0.8 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) direction and (2) order_by parameters.
0
Attacker Value
Unknown
CVE-2009-2783
Disclosure Date: August 17, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.3.3 allow remote attackers to inject arbitrary web script or HTML via the (1) op parameter to modules/pm/viewpmsg.php and (2) query string to modules/profile/user.php.
0
Attacker Value
Unknown
CVE-2008-6884
Disclosure Date: July 31, 2009 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in XOOPS 2.3.1, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the xoopsConfig[language] parameter to (1) blocks.php and (2) main.php in xoops_lib/modules/protector/.
0