Show filters
200 Total Results
Displaying 141-150 of 200
Sort by:
Attacker Value
Unknown

CVE-2013-7352

Disclosure Date: April 02, 2014 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the show_statuses[] parameter, related to CVE-2013-2945.
0
Attacker Value
Unknown

CVE-2013-2945

Disclosure Date: April 02, 2014 (last updated October 05, 2023)
SQL injection vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote authenticated administrators to execute arbitrary SQL commands via the show_statuses[] parameter. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands.
0
Attacker Value
Unknown

CVE-2014-2311

Disclosure Date: March 11, 2014 (last updated October 05, 2023)
SQL injection vulnerability in modx.class.php in MODX Revolution 2.0.0 before 2.2.13 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-2080

Disclosure Date: March 01, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in manager/templates/default/header.tpl in ModX Revolution before 2.2.11 allows remote attackers to inject arbitrary web script or HTML via the "a" parameter.
0
Attacker Value
Unknown

CVE-2014-1223

Disclosure Date: February 27, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in controlpanel/loading.aspx in Telligent Evolution before 6.1.19.36103, 7.x before 7.1.12.36162, 7.5.x, and 7.6.x before 7.6.7.36651 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2014-1639

Disclosure Date: January 28, 2014 (last updated October 05, 2023)
syncevo/installcheck-local.sh in syncevolution before 1.3.99.7 uses mktemp to create a safe temporary file but appends a suffix to the original filename and writes to this new filename, which allows local users to overwrite arbitrary files via a symlink attack on the new filename.
0
Attacker Value
Unknown

CVE-2011-3201

Disclosure Date: March 08, 2013 (last updated October 05, 2023)
GNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the attachment parameter to a mailto: URL, which attaches the file to the email.
0
Attacker Value
Unknown

CVE-2012-5911

Disclosure Date: November 17, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in blogs/blog1.php in b2evolution 4.1.3 allows remote attackers to inject arbitrary web script or HTML via the message body.
0
Attacker Value
Unknown

CVE-2012-5910

Disclosure Date: November 17, 2012 (last updated October 05, 2023)
SQL injection vulnerability in blogs/htsrv/viewfile.php in b2evolution 4.1.3 allows remote authenticated users to execute arbitrary SQL commands via the root parameter.
0
Attacker Value
Unknown

CVE-2010-5278

Disclosure Date: October 07, 2012 (last updated October 05, 2023)
Directory traversal vulnerability in manager/controllers/default/resource/tvs.php in MODx Revolution 2.0.2-pl, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the class_key parameter. NOTE: some of these details are obtained from third party information.
0