Show filters
98 Total Results
Displaying 21-30 of 98
Sort by:
Attacker Value
Unknown
CVE-2008-6885
Disclosure Date: July 31, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in pmlite.php in XOOPS 2.3.1 and 2.3.2a allows remote attackers to inject arbitrary web script or HTML via a STYLE attribute in a URL BBcode tag in a private message.
0
Attacker Value
Unknown
CVE-2008-5665
Disclosure Date: December 19, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the xhresim module in XOOPS allows remote attackers to execute arbitrary SQL commands via the no parameter.
0
Attacker Value
Unknown
CVE-2008-5321
Disclosure Date: December 03, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in GesGaleri, a module for XOOPS, allows remote attackers to execute arbitrary SQL commands via the no parameter.
0
Attacker Value
Unknown
CVE-2008-4653
Disclosure Date: October 22, 2008 (last updated October 04, 2023)
SQL injection vulnerability in makale.php in Makale 0.26 and possibly other versions, a module for XOOPS, allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2008-3560
Disclosure Date: August 08, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in kshop_search.php in the Kshop module 2.22 for Xoops allows remote attackers to inject arbitrary web script or HTML via the search parameter.
0
Attacker Value
Unknown
CVE-2008-3296
Disclosure Date: July 25, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in modules/system/admin.php in XOOPS 2.0.18 1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the fct parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2008-3295
Disclosure Date: July 25, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in modules/system/admin.php in XOOPS 2.0.18.1 allows remote attackers to inject arbitrary web script or HTML via the fct parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2008-2094
Disclosure Date: May 06, 2008 (last updated October 04, 2023)
SQL injection vulnerability in article.php in the Article module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown
CVE-2008-2035
Disclosure Date: April 30, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Bluemoon, Inc. (1) BackPack 0.91 and earlier, (2) BmSurvey 0.84 and earlier, (3) newbb_fileup 1.83 and earlier, (4) News_embed (news_fileup) 1.44 and earlier, and (5) PopnupBlog 3.19 and earlier modules for XOOPS 2.0.x, XOOPS Cube 2.1, and ImpressCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-1351
Disclosure Date: March 17, 2008 (last updated October 04, 2023)
SQL injection vulnerability in the Tutorials 2.1b module for XOOPS allows remote attackers to execute arbitrary SQL commands via the tid parameter to printpage.php, which is accessible directly or through a printpage action to index.php.
0