Show filters
112 Total Results
Displaying 101-110 of 112
Sort by:
Attacker Value
Unknown

CVE-2012-3791

Disclosure Date: June 21, 2012 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Simple Web Content Management System 1.1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) item_delete.php, (2) item_status.php, (3) item_detail.php, (4) item_modify.php, or (5) item_position.php in admin/; or (6) status parameter to admin/item_status.php.
0
Attacker Value
Unknown

CVE-2011-1229

Disclosure Date: April 13, 2011 (last updated October 04, 2023)
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
0
Attacker Value
Unknown

CVE-2007-5233

Disclosure Date: October 05, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in Web Template Management System 1.3 allows remote attackers to execute arbitrary SQL commands via the id parameter in a readmore action.
0
Attacker Value
Unknown

CVE-2006-5447

Disclosure Date: October 23, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in DEV Web Management System (WMS) 1.5 allows remote attackers to inject arbitrary web script or HTML via the action parameter.
0
Attacker Value
Unknown

CVE-2006-0886

Disclosure Date: February 25, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in register.php in DEV web management system 1.5 allows remote attackers to inject arbitrary web script or HTML via the "City/Region" field (mesto variable). NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2005-4554

Disclosure Date: December 28, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in DEV web management system 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter in an openforum action (openforum.php) in index.php, (2) cat parameter in getfile.php, and (3) target parameter in download_now.php.
0
Attacker Value
Unknown

CVE-2005-4555

Disclosure Date: December 28, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in add.php in DEV web management system 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) ENTER_ARTICLE_TITLE, (2) SPECIFY_ZONE, (3) ENTER_ARTICLE_HEADER, and (4) ENTER_ARTICLE_BODY indices in the language array parameter.
0
Attacker Value
Unknown

CVE-2005-2489

Disclosure Date: August 07, 2005 (last updated February 22, 2025)
Web Content Management News System allows remote attackers to create arbitrary accounts and gain privileges via a direct request to Admin/Users/AddModifyInput.php.
0
Attacker Value
Unknown

CVE-2005-2488

Disclosure Date: August 07, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Web Content Management News System allows remote attackers to inject arbitrary web script or HTML via (1) the strRootpath parameter to validsession.php or (2) the strTable parameter to Admin/News/List.php.
0
Attacker Value
Unknown

CVE-2004-2210

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Express-Web Content Management System (CMS) allow remote attackers to steal cookie-based authentication information and possibly perform other exploits via the (1) n, (2) b, (3) e, or (4) a parameters to default.asp, (5) the Referer header in an HTTP request to login.asp, or (6) the email parameter to subscribe/default.asp.
0