Show filters
194 Total Results
Displaying 191-194 of 194
Sort by:
Attacker Value
Unknown
CVE-2006-1237
Disclosure Date: March 15, 2006 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in DSNewsletter 1.0, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the email parameter to (1) include/sub.php, (2) include/confirm.php, or (3) include/unconfirm.php.
0
Attacker Value
Unknown
CVE-2005-1750
Disclosure Date: May 25, 2005 (last updated February 22, 2025)
SQL injection vulnerability in login.asp in ezdwc NewsletterEz 3.0 allows remote attackers to execute arbitrary SQL commands via the password parameter.
0
Attacker Value
Unknown
CVE-2004-0621
Disclosure Date: December 06, 2004 (last updated February 22, 2025)
admin.php in Newsletter ZWS allows remote attackers to gain administrative privileges via a list_user operation with the ulevel parameter set to 1 (administrator level), which lists all users and their passwords.
0
Attacker Value
Unknown
CVE-2002-1887
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in customize.php for phpMyNewsletter 0.6.10 allows remote attackers to execute arbitrary PHP code via the l parameter.
0