Show filters
194 Total Results
Displaying 171-180 of 194
Sort by:
Attacker Value
Unknown

CVE-2008-0683

Disclosure Date: February 12, 2008 (last updated October 04, 2023)
SQL injection vulnerability in shiftthis-preview.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the newsletter parameter.
0
Attacker Value
Unknown

CVE-2008-0510

Disclosure Date: January 31, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the Newsletter (com_newsletter) component for Mambo 4.5 and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter.
0
Attacker Value
Unknown

CVE-2007-6585

Disclosure Date: December 28, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in confirmUnsubscription.php in NmnNewsletter 1.0.7 allows remote attackers to execute arbitrary PHP code via a URL in the output parameter.
0
Attacker Value
Unknown

CVE-2007-6301

Disclosure Date: December 10, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in compose.php in OpenNewsletter 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the type parameter.
0
Attacker Value
Unknown

CVE-2007-5458

Disclosure Date: October 14, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the newsletter module 1.0 for KwsPHP, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the newsletter parameter.
0
Attacker Value
Unknown

CVE-2007-2969

Disclosure Date: June 01, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in newsletter.php in WAnewsletter 2.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the waroot parameter.
0
Attacker Value
Unknown

CVE-2007-2372

Disclosure Date: April 30, 2007 (last updated October 04, 2023)
admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier prints a Location header but does not exit when administrative credentials are missing, which allows remote attackers to compose an e-mail message via a post with the subject, message, format, and list_id fields; and send the message via a direct request for the MsgId value under admin/.
0
Attacker Value
Unknown

CVE-2007-2371

Disclosure Date: April 30, 2007 (last updated October 04, 2023)
admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification before login, which allows remote attackers to cause a denial of service (loss of configuration data), and possibly perform direct static code injection, via a saveGlobalconfig action.
0
Attacker Value
Unknown

CVE-2007-1696

Disclosure Date: March 27, 2007 (last updated October 04, 2023)
SQL injection vulnerability in ViewNewspapers.asp in Active Newsletter 4.3 and earlier allows remote attackers to execute arbitrary SQL commands via the NewsPaperID parameter.
0
Attacker Value
Unknown

CVE-2006-6786

Disclosure Date: December 28, 2006 (last updated October 04, 2023)
Open Newsletter 2.5 and earlier allows remote authenticated administrators to execute arbitrary PHP code by inserting the code into the email parameter to (1) subscribe.php or (2) unsubscribe.php.
0