Show filters
98 Total Results
Displaying 21-30 of 98
Sort by:
Attacker Value
Unknown

CVE-2008-6885

Disclosure Date: July 31, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in pmlite.php in XOOPS 2.3.1 and 2.3.2a allows remote attackers to inject arbitrary web script or HTML via a STYLE attribute in a URL BBcode tag in a private message.
0
Attacker Value
Unknown

CVE-2008-5665

Disclosure Date: December 19, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the xhresim module in XOOPS allows remote attackers to execute arbitrary SQL commands via the no parameter.
0
Attacker Value
Unknown

CVE-2008-5321

Disclosure Date: December 03, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in GesGaleri, a module for XOOPS, allows remote attackers to execute arbitrary SQL commands via the no parameter.
0
Attacker Value
Unknown

CVE-2008-4653

Disclosure Date: October 22, 2008 (last updated October 04, 2023)
SQL injection vulnerability in makale.php in Makale 0.26 and possibly other versions, a module for XOOPS, allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-3560

Disclosure Date: August 08, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in kshop_search.php in the Kshop module 2.22 for Xoops allows remote attackers to inject arbitrary web script or HTML via the search parameter.
0
Attacker Value
Unknown

CVE-2008-3296

Disclosure Date: July 25, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in modules/system/admin.php in XOOPS 2.0.18 1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the fct parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2008-3295

Disclosure Date: July 25, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in modules/system/admin.php in XOOPS 2.0.18.1 allows remote attackers to inject arbitrary web script or HTML via the fct parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2008-2094

Disclosure Date: May 06, 2008 (last updated October 04, 2023)
SQL injection vulnerability in article.php in the Article module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2008-2035

Disclosure Date: April 30, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Bluemoon, Inc. (1) BackPack 0.91 and earlier, (2) BmSurvey 0.84 and earlier, (3) newbb_fileup 1.83 and earlier, (4) News_embed (news_fileup) 1.44 and earlier, and (5) PopnupBlog 3.19 and earlier modules for XOOPS 2.0.x, XOOPS Cube 2.1, and ImpressCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-1351

Disclosure Date: March 17, 2008 (last updated October 04, 2023)
SQL injection vulnerability in the Tutorials 2.1b module for XOOPS allows remote attackers to execute arbitrary SQL commands via the tid parameter to printpage.php, which is accessible directly or through a printpage action to index.php.
0