Show filters
194 Total Results
Displaying 131-140 of 194
Sort by:
Attacker Value
Unknown
CVE-2007-5091
Disclosure Date: September 26, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in eGroupWare 1.4.001 allow remote attackers to inject arbitrary web script or HTML via the cat_data[color] parameter to (1) preferences/inc/class.uicategories.inc.php and (2) admin/inc/class.uicategories.inc.php.
0
Attacker Value
Unknown
CVE-2007-4554
Disclosure Date: August 28, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in tiki-remind_password.php in Tikiwiki (aka Tiki CMS/Groupware) 1.9.7 allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: this issue might be related to CVE-2006-2635.7.
0
Attacker Value
Unknown
CVE-2007-4123
Disclosure Date: August 01, 2007 (last updated October 04, 2023)
The Groupmax Scheduler_Facilities management tool in Hitachi Groupmax Groupware Server 07-00-/F through 07-32-/A before 20070731 does not properly manage schedule server configuration data, which might allow attackers to obtain sensitive information via unspecified vectors.
0
Attacker Value
Unknown
CVE-2007-3155
Disclosure Date: June 11, 2007 (last updated October 04, 2023)
Unspecified vulnerability in eGroupWare before 1.2.107-2 has unknown impact and attack vectors related to ADOdb. NOTE: due to lack of details from the vendor, it is uncertain whether this issue is already covered by another CVE identifier.
0
Attacker Value
Unknown
CVE-2007-3154
Disclosure Date: June 11, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Walter Zorn wz_tooltip.js (aka wz_tooltips) before 4.01, as used by eGroupWare before 1.2.107-2 and other packages, has unknown impact and remote attack vectors.
0
Attacker Value
Unknown
CVE-2007-2720
Disclosure Date: May 16, 2007 (last updated October 04, 2023)
Group-Office before 2.16-13 does not properly validate user IDs, which allows remote attackers to obtain sensitive information via certain requests for (1) message.php and (2) messages.php in modules/email/. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2007-1679
Disclosure Date: March 26, 2007 (last updated November 08, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Horde Groupware Webmail 1.0 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors in (1) imp/search.php and (2) ingo/rule.php. NOTE: this issue has been disputed by the vendor, noting that the search.php issue was resolved in CVE-2006-4255, and attackers can only use rule.php to inject XSS into their own pages
0
Attacker Value
Unknown
CVE-2007-0579
Disclosure Date: January 30, 2007 (last updated October 04, 2023)
Unspecified vulnerability in the calendar component in Horde Groupware Webmail Edition before 1.0, and Groupware before 1.0, allows remote attackers to include certain files via unspecified vectors. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2006-6457
Disclosure Date: December 11, 2006 (last updated October 04, 2023)
tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other versions allows remote attackers to obtain sensitive information (MySQL username and password) via an invalid (large or negative) ver parameter, which leaks the information in an error message.
0
Attacker Value
Unknown
CVE-2006-6168
Disclosure Date: November 29, 2006 (last updated October 04, 2023)
tiki-register.php in TikiWiki before 1.9.7 allows remote attackers to trigger "notification-spam" via certain vectors such as a comma-separated list of addresses in the email field, related to lack of "a minimal check on email."
0