Show filters
29 Total Results
Displaying 21-29 of 29
Sort by:
Attacker Value
Unknown

CVE-2006-2545

Disclosure Date: May 23, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Xtreme Topsites 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in stats.php and (2) unspecified inputs in lostid.php, probably the searchthis parameter. NOTE: one or more of these vectors might be resultant from SQL injection.
0
Attacker Value
Unknown

CVE-2006-2339

Disclosure Date: May 12, 2006 (last updated October 04, 2023)
SQL injection vulnerability in index.php in evoTopsites 2.x and evoTopsites Pro 2.x allows remote attackers to execute arbitrary SQL commands via the (1) cat_id and (2) id parameters.
0
Attacker Value
Unknown

CVE-2006-2149

Disclosure Date: May 03, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in sources/lostpw.php in Aardvark Topsites PHP 4.2.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the CONFIG[path] parameter, as demonstrated by including a GIF that contains PHP code.
0
Attacker Value
Unknown

CVE-2006-1878

Disclosure Date: April 20, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in phpFaber TopSites allows remote attackers to inject arbitrary web script or HTML via the page parameter.
0
Attacker Value
Unknown

CVE-2006-0654

Disclosure Date: February 13, 2006 (last updated February 22, 2025)
check.php in Hinton Design phpht Topsites 1.3 does not validate passwords when using cookies, which allows remote attackers to bypass authentication via unspecified cookies.
0
Attacker Value
Unknown

CVE-2006-0655

Disclosure Date: February 13, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in (1) link_edited.php and (2) link_added.php in Hinton Design phpht Topsites 1.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2006-0653

Disclosure Date: February 13, 2006 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in Hinton Design phpht Topsites 1.3 allow remote attackers to execute arbitrary SQL commands via multiple vectors including the username parameter.
0
Attacker Value
Unknown

CVE-2006-0184

Disclosure Date: January 12, 2006 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in AspTopSites allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to goto.asp or (2) password parameter to includeloginuser.asp.
0
Attacker Value
Unknown

CVE-2005-3515

Disclosure Date: November 06, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in recommend.php in Chipmunk Topsites script allows remote attackers to inject arbitrary web script or HTML via the ID parameter.
0