Show filters
194 Total Results
Displaying 111-120 of 194
Sort by:
Attacker Value
Unknown

CVE-2008-5319

Disclosure Date: December 03, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Tikiwiki before 2.2 has unknown impact and attack vectors related to tiki-error.php, a different issue than CVE-2008-3653.
0
Attacker Value
Unknown

CVE-2008-4165

Disclosure Date: September 22, 2008 (last updated October 04, 2023)
admin/user/create_user.php in Kolab Groupware Server 1.0.0 places a user password in an HTTP GET request, which allows local administrators, and possibly remote attackers, to obtain cleartext passwords by reading the ssl_access_log file or the referer string.
0
Attacker Value
Unknown

CVE-2008-3654

Disclosure Date: August 13, 2008 (last updated October 04, 2023)
Unspecified vulnerability in TikiWiki CMS/Groupware before 2.0 allows attackers to obtain "path and PHP configuration" via unknown vectors.
0
Attacker Value
Unknown

CVE-2008-3650

Disclosure Date: August 13, 2008 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in Horde Groupware Webmail before Edition 1.1.1 (final) have unknown impact and attack vectors related to "unescaped output," possibly cross-site scripting (XSS), in the (1) object browser and (2) contact view.
0
Attacker Value
Unknown

CVE-2008-3653

Disclosure Date: August 13, 2008 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in TikiWiki CMS/Groupware before 2.0 have unknown impact and attack vectors.
0
Attacker Value
Unknown

CVE-2008-2783

Disclosure Date: June 19, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Horde Groupware, Groupware Webmail Edition, and Kronolith allow remote attackers to inject arbitrary web script or HTML via the timestamp parameter to (1) week.php, (2) workweek.php, and (3) day.php; and (4) the horde parameter in the PATH_INFO to the default URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2008-2041

Disclosure Date: April 30, 2008 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in eGroupWare before 1.4.004 have unspecified attack vectors and "grave" impact when the web server has write access to a directory under the web document root.
0
Attacker Value
Unknown

CVE-2008-1974

Disclosure Date: April 27, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in addevent.php in Horde Kronolith 2.1.7, Groupware Webmail Edition 1.0.6, and Groupware 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the url parameter.
0
Attacker Value
Unknown

CVE-2008-1502

Disclosure Date: March 25, 2008 (last updated October 04, 2023)
The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and other products, allows remote attackers to bypass HTML filtering and conduct cross-site scripting (XSS) attacks via a string containing crafted URL protocols.
0
Attacker Value
Unknown

CVE-2008-1284

Disclosure Date: March 11, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in Horde 3.1.6, Groupware before 1.0.5, and Groupware Webmail Edition before 1.0.6, when running with certain configurations, allows remote authenticated users to read and execute arbitrary files via ".." sequences and a null byte in the theme name.
0