Show filters
177 Total Results
Displaying 161-170 of 177
Sort by:
Attacker Value
Unknown
CVE-2008-6492
Disclosure Date: March 20, 2009 (last updated October 04, 2023)
Unrestricted file upload vulnerability in process.php in Tizag Countdown Creator 3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via index.php, then accessing the uploaded file via a direct request to the file in pics/. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2008-4377
Disclosure Date: October 01, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.asp in Creative Mind Creator CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the sideid parameter.
0
Attacker Value
Unknown
CVE-2007-6136
Disclosure Date: November 27, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in index.php in M2Scripts MySpace Scripts Poll Creator allow remote attackers to inject arbitrary web script or HTML via the (1) title, (2) intro, and (3) question parameters, and (4) unspecified answer parameters, in a create_new action. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2007-1779
Disclosure Date: March 30, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in the MySQL back-end in Advanced Website Creator (AWC) before 1.9.0 might allow remote attackers to execute arbitrary SQL commands via unspecified parameters, related to use of mysql_escape_string instead of mysql_real_escape_string.
0
Attacker Value
Unknown
CVE-2007-1459
Disclosure Date: March 14, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in WebCreator 0.2.6-rc3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the moddir parameter to (1) content/load.inc.php, (2) config/load.inc.php, (3) http/load.inc.php, and unspecified other files.
0
Attacker Value
Unknown
CVE-2006-7136
Disclosure Date: March 07, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in PHP Poll Creator (phpPC) 1.04 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the relativer_pfad parameter to (1) poll.php, (2) poll_kommentar.php, and (3) poll_sm.php, different vectors and version than CVE-2005-1755.
0
Attacker Value
Unknown
CVE-2006-7135
Disclosure Date: March 07, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in lib/functions.inc.php in PHP Poll Creator (phpPC) 1.04 allows remote attackers to execute arbitrary PHP code via a URL in the relativer_pfad parameter, a different vector and version than CVE-2005-1755. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2006-5797
Disclosure Date: November 08, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in default.asp in Xenis.creator CMS allow remote attackers to execute arbitrary SQL commands via the (1) nav, (2) s, or (3) print parameters.
0
Attacker Value
Unknown
CVE-2006-5799
Disclosure Date: November 08, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in default.asp in xenis.creator CMS allow remote attackers to inject arbitrary web script or HTML via the (1) contid or (2) search parameters.
0
Attacker Value
Unknown
CVE-2006-5798
Disclosure Date: November 08, 2006 (last updated October 04, 2023)
SQL injection vulnerability in default.asp in Xenis.creator CMS allows remote attackers to execute arbitrary SQL commands via the contid parameter.
0