Show filters
61 Total Results
Displaying 21-30 of 61
Sort by:
Attacker Value
Unknown
CVE-2009-1033
Disclosure Date: March 20, 2009 (last updated October 04, 2023)
SQL injection vulnerability in misc.php in DeluxeBB 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the qorder parameter, a different vector than CVE-2005-2989 and CVE-2006-2503.
0
Attacker Value
Unknown
CVE-2008-6146
Disclosure Date: February 16, 2009 (last updated October 04, 2023)
SQL injection vulnerability in pm.php in DeluxeBB 1.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via a delete##### parameter in a Delete action, a different vector than CVE-2005-2989.
0
Attacker Value
Unknown
CVE-2009-0373
Disclosure Date: January 30, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the ElearningForce Flash Magazine Deluxe (com_flashmagazinedeluxe) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mag_id parameter in a magazine action to index.php.
0
Attacker Value
Unknown
CVE-2008-4181
Disclosure Date: September 23, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in includes/xml.php in the Netenberg Fantastico De Luxe module before 2.10.4 r19 for cPanel, when cPanel PHP Register Globals is enabled, allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) or absolute pathname in the fantasticopath parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.
0
Attacker Value
Unknown
CVE-2008-3136
Disclosure Date: July 10, 2008 (last updated October 04, 2023)
SQL injection vulnerability in catalogue.php in AShop Deluxe 4.x allows remote attackers to execute arbitrary SQL commands via the cat parameter.
0
Attacker Value
Unknown
CVE-2008-2195
Disclosure Date: May 14, 2008 (last updated October 04, 2023)
Static code injection vulnerability in admincp.php in DeluxeBB 1.2 and earlier allows remote authenticated administrators to inject arbitrary PHP code into logs/cp.php via the URI.
0
Attacker Value
Unknown
CVE-2008-2194
Disclosure Date: May 14, 2008 (last updated October 04, 2023)
SQL injection vulnerability in forums.php in DeluxeBB 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the sort parameter.
0
Attacker Value
Unknown
CVE-2008-0439
Disclosure Date: January 23, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in templates/default/admincp/attachments_header.php in DeluxeBB 1.1 allows remote attackers to inject arbitrary web script or HTML via the lang_listofmatches parameter.
0
Attacker Value
Unknown
CVE-2007-6237
Disclosure Date: December 04, 2007 (last updated October 04, 2023)
cp.php in DeluxeBB 1.09 does not verify that the membercookie parameter corresponds to the authenticated member during a profile update, which allows remote authenticated users to change the e-mail addresses of arbitrary accounts via a modified membercookie parameter, a different vector than CVE-2006-4078. NOTE: this can be leveraged for administrative access by requesting password-reset e-mail through a lostpw action to misc.php.
0
Attacker Value
Unknown
CVE-2007-6162
Disclosure Date: November 29, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in FMDeluxe 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a category action.
0