Show filters
194 Total Results
Displaying 111-120 of 194
Sort by:
Attacker Value
Unknown
CVE-2008-5319
Disclosure Date: December 03, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Tikiwiki before 2.2 has unknown impact and attack vectors related to tiki-error.php, a different issue than CVE-2008-3653.
0
Attacker Value
Unknown
CVE-2008-4165
Disclosure Date: September 22, 2008 (last updated October 04, 2023)
admin/user/create_user.php in Kolab Groupware Server 1.0.0 places a user password in an HTTP GET request, which allows local administrators, and possibly remote attackers, to obtain cleartext passwords by reading the ssl_access_log file or the referer string.
0
Attacker Value
Unknown
CVE-2008-3654
Disclosure Date: August 13, 2008 (last updated October 04, 2023)
Unspecified vulnerability in TikiWiki CMS/Groupware before 2.0 allows attackers to obtain "path and PHP configuration" via unknown vectors.
0
Attacker Value
Unknown
CVE-2008-3650
Disclosure Date: August 13, 2008 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in Horde Groupware Webmail before Edition 1.1.1 (final) have unknown impact and attack vectors related to "unescaped output," possibly cross-site scripting (XSS), in the (1) object browser and (2) contact view.
0
Attacker Value
Unknown
CVE-2008-3653
Disclosure Date: August 13, 2008 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in TikiWiki CMS/Groupware before 2.0 have unknown impact and attack vectors.
0
Attacker Value
Unknown
CVE-2008-2783
Disclosure Date: June 19, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Horde Groupware, Groupware Webmail Edition, and Kronolith allow remote attackers to inject arbitrary web script or HTML via the timestamp parameter to (1) week.php, (2) workweek.php, and (3) day.php; and (4) the horde parameter in the PATH_INFO to the default URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2008-2041
Disclosure Date: April 30, 2008 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in eGroupWare before 1.4.004 have unspecified attack vectors and "grave" impact when the web server has write access to a directory under the web document root.
0
Attacker Value
Unknown
CVE-2008-1974
Disclosure Date: April 27, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in addevent.php in Horde Kronolith 2.1.7, Groupware Webmail Edition 1.0.6, and Groupware 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the url parameter.
0
Attacker Value
Unknown
CVE-2008-1502
Disclosure Date: March 25, 2008 (last updated October 04, 2023)
The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and other products, allows remote attackers to bypass HTML filtering and conduct cross-site scripting (XSS) attacks via a string containing crafted URL protocols.
0
Attacker Value
Unknown
CVE-2008-1284
Disclosure Date: March 11, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in Horde 3.1.6, Groupware before 1.0.5, and Groupware Webmail Edition before 1.0.6, when running with certain configurations, allows remote authenticated users to read and execute arbitrary files via ".." sequences and a null byte in the theme name.
0