Show filters
194 Total Results
Displaying 161-170 of 194
Sort by:
Attacker Value
Unknown
CVE-2010-1024
Disclosure Date: March 19, 2010 (last updated October 04, 2023)
SQL injection vulnerability in the TGM-Newsletter (tgm_newsletter) extension 0.0.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2010-0467
Disclosure Date: February 02, 2010 (last updated January 27, 2024)
Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a ccnewsletter action to index.php.
0
Attacker Value
Unknown
CVE-2009-2602
Disclosure Date: July 27, 2009 (last updated October 04, 2023)
R2 Newsletter Lite, Pro, and Stats stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for admin.mdb.
0
Attacker Value
Unknown
CVE-2008-6861
Disclosure Date: July 14, 2009 (last updated October 04, 2023)
Xigla Software Absolute Newsletter 6.0 and 6.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
0
Attacker Value
Unknown
CVE-2008-6286
Disclosure Date: February 25, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in SubscriberStart.asp in Active Newsletter 4.3 allow remote attackers to execute arbitrary SQL commands via (1) the email parameter (aka username or E-mail field), or (2) the password parameter (aka password field), to (a) Subscriber.asp or (b) start.asp. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2009-0340
Disclosure Date: January 29, 2009 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in Simple PHP Newsletter 1.5 allow remote attackers to read arbitrary files via a .. (dot dot) in the olang parameter to (1) mail.php and (2) mailbar.php.
0
Attacker Value
Unknown
CVE-2008-5570
Disclosure Date: December 15, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in PHP Multiple Newsletters 2.7, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.
0
Attacker Value
Unknown
CVE-2008-5566
Disclosure Date: December 15, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in Triangle Solutions PHP Multiple Newsletters 2.7 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
0
Attacker Value
Unknown
CVE-2008-4625
Disclosure Date: October 21, 2008 (last updated October 04, 2023)
SQL injection vulnerability in stnl_iframe.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the newsletter parameter, a different vector than CVE-2008-0683.
0
Attacker Value
Unknown
CVE-2008-1295
Disclosure Date: March 12, 2008 (last updated October 04, 2023)
SQL injection vulnerability in archives.php in Gregory Kokanosky (aka Greg's Place) phpMyNewsletter 0.8 beta 5 and earlier allows remote attackers to execute arbitrary SQL commands via the msg_id parameter.
0