Show filters
117 Total Results
Displaying 111-117 of 117
Sort by:
Attacker Value
Unknown
CVE-2009-3825
Disclosure Date: October 28, 2009 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in GenCMS 2006 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) p parameter to show.php and the (2) Template parameter to admin/pages/SiteNew.php.
0
Attacker Value
Unknown
CVE-2008-4648
Disclosure Date: October 22, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in Elxis CMS 2008.1 revision 2204 allows remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO or the (2) option, (3) Itemid, (4) id, (5) task, (6) bid, and (7) contact_id parameters. NOTE: the error might be located in modules/mod_language.php, and index.php might be the interaction point.
0
Attacker Value
Unknown
CVE-2008-4649
Disclosure Date: October 22, 2008 (last updated October 04, 2023)
Session fixation vulnerability in Elxis CMS 2008.1 revision 2204 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
0
Attacker Value
Unknown
CVE-2008-3026
Disclosure Date: July 07, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in OneClick CMS (aka Sisplet CMS) 2008-01-24 allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown
CVE-2007-3250
Disclosure Date: June 18, 2007 (last updated October 04, 2023)
SQL injection vulnerability in mod_banners.php in Elxis CMS before 2006.4 20070613 allows remote attackers to execute arbitrary SQL commands via the mb_tracker cookie. NOTE: the product was patched without updating the version number; later downloads of 2006.4 are not affected.
0
Attacker Value
Unknown
CVE-2007-2009
Disclosure Date: April 12, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in index.php in SimpCMS Light 04.10.2007 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the site parameter.
0
Attacker Value
Unknown
CVE-2006-5625
Disclosure Date: October 31, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in wwwdev/nxheader.inc.php in N/X 2002 Professional Edition Web Content Management System (WCMS) 4.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the c[path] parameter.
0