Show filters
143 Total Results
Displaying 131-140 of 143
Sort by:
Attacker Value
Unknown
CVE-2008-5195
Disclosure Date: November 21, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in SebracCMS (sbcms) 0.4 allow remote attackers to execute arbitrary SQL commands via (1) the recid parameter to cms/form/read.php, (2) the uname parameter to cms/index.php, and other unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-0478
Disclosure Date: January 29, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in SetCMS 3.6.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the set parameter, as demonstrated by sending a certain CLIENT_IP HTTP header in an enter action to index.php, and injecting PHP sequences into files/enter.set, which is then included by index.php.
0
Attacker Value
Unknown
CVE-2007-6488
Disclosure Date: December 20, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in (1) the dir[classes] parameter to sitemap.xml.php or (2) the error parameter to errors.php.
0
Attacker Value
Unknown
CVE-2007-6490
Disclosure Date: December 20, 2007 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in Falcon Series One CMS 1.4.3 allows remote attackers to change a password via a certain changepass action to index.php.
0
Attacker Value
Unknown
CVE-2007-6489
Disclosure Date: December 20, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to inject arbitrary web script or HTML via the (1) gb_mail, (2) gb_name, and (3) gb_text parameters in a guestbook action to index.php, and unspecified other vectors.
0
Attacker Value
Unknown
CVE-2007-5186
Disclosure Date: October 03, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in index.php in Segue CMS 1.8.4 and earlier, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the themesdir parameter, a different vector than CVE-2006-5497. NOTE: this issue was disputed, but the dispute was retracted after additional analysis.
0
Attacker Value
Unknown
CVE-2007-0846
Disclosure Date: February 08, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in forum.php in Open Tibia Server CMS (OTSCMS) 2.1.5 and earlier allows remote attackers to inject arbitrary HTML or web script via the name parameter.
0
Attacker Value
Unknown
CVE-2007-0847
Disclosure Date: February 08, 2007 (last updated October 04, 2023)
SQL injection vulnerability in mod/PM/reply.php in Open Tibia Server CMS (OTSCMS) 2.1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to priv.php.
0
Attacker Value
Unknown
CVE-2006-5722
Disclosure Date: November 04, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Segue CMS 1.5.9 and earlier, when magic_quotes_gpc is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the theme parameter to (1) themesettings.php or (2) index.php, a different vector than CVE-2006-5497. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2006-5490
Disclosure Date: October 25, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Segue Content Management System (CMS) before 1.5.8 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
0