Show filters
194 Total Results
Displaying 131-140 of 194
Sort by:
Attacker Value
Unknown

CVE-2007-5091

Disclosure Date: September 26, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in eGroupWare 1.4.001 allow remote attackers to inject arbitrary web script or HTML via the cat_data[color] parameter to (1) preferences/inc/class.uicategories.inc.php and (2) admin/inc/class.uicategories.inc.php.
0
Attacker Value
Unknown

CVE-2007-4554

Disclosure Date: August 28, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in tiki-remind_password.php in Tikiwiki (aka Tiki CMS/Groupware) 1.9.7 allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: this issue might be related to CVE-2006-2635.7.
0
Attacker Value
Unknown

CVE-2007-4123

Disclosure Date: August 01, 2007 (last updated October 04, 2023)
The Groupmax Scheduler_Facilities management tool in Hitachi Groupmax Groupware Server 07-00-/F through 07-32-/A before 20070731 does not properly manage schedule server configuration data, which might allow attackers to obtain sensitive information via unspecified vectors.
0
Attacker Value
Unknown

CVE-2007-3155

Disclosure Date: June 11, 2007 (last updated October 04, 2023)
Unspecified vulnerability in eGroupWare before 1.2.107-2 has unknown impact and attack vectors related to ADOdb. NOTE: due to lack of details from the vendor, it is uncertain whether this issue is already covered by another CVE identifier.
0
Attacker Value
Unknown

CVE-2007-3154

Disclosure Date: June 11, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Walter Zorn wz_tooltip.js (aka wz_tooltips) before 4.01, as used by eGroupWare before 1.2.107-2 and other packages, has unknown impact and remote attack vectors.
0
Attacker Value
Unknown

CVE-2007-2720

Disclosure Date: May 16, 2007 (last updated October 04, 2023)
Group-Office before 2.16-13 does not properly validate user IDs, which allows remote attackers to obtain sensitive information via certain requests for (1) message.php and (2) messages.php in modules/email/. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2007-1679

Disclosure Date: March 26, 2007 (last updated November 08, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Horde Groupware Webmail 1.0 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors in (1) imp/search.php and (2) ingo/rule.php. NOTE: this issue has been disputed by the vendor, noting that the search.php issue was resolved in CVE-2006-4255, and attackers can only use rule.php to inject XSS into their own pages
0
Attacker Value
Unknown

CVE-2007-0579

Disclosure Date: January 30, 2007 (last updated October 04, 2023)
Unspecified vulnerability in the calendar component in Horde Groupware Webmail Edition before 1.0, and Groupware before 1.0, allows remote attackers to include certain files via unspecified vectors. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2006-6457

Disclosure Date: December 11, 2006 (last updated October 04, 2023)
tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other versions allows remote attackers to obtain sensitive information (MySQL username and password) via an invalid (large or negative) ver parameter, which leaks the information in an error message.
0
Attacker Value
Unknown

CVE-2006-6168

Disclosure Date: November 29, 2006 (last updated October 04, 2023)
tiki-register.php in TikiWiki before 1.9.7 allows remote attackers to trigger "notification-spam" via certain vectors such as a comma-separated list of addresses in the email field, related to lack of "a minimal check on email."
0