Show filters
320 Total Results
Displaying 271-280 of 320
Sort by:
Attacker Value
Unknown
CVE-2006-7146
Disclosure Date: March 07, 2007 (last updated November 08, 2023)
PHP remote file inclusion vulnerability in bug.php in Leicestershire communityPortals 1.0 build 20051018 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cp_root_path parameter, a different vector than CVE-2006-5280. NOTE: CVE disputes this issue, since bug.php is not in communityPortals source distributions
0
Attacker Value
Unknown
CVE-2006-7068
Disclosure Date: March 02, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in CliServ Web Community 0.65 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cl_headers parameter to (1) menu.php3 and (2) login.php3.
0
Attacker Value
Unknown
CVE-2007-0925
Disclosure Date: February 14, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in search/SearchResults.aspx in Community Server allows remote attackers to inject arbitrary web script or HTML via the q parameter.
0
Attacker Value
Unknown
CVE-2007-0538
Disclosure Date: January 29, 2007 (last updated October 04, 2023)
Telligent Community Server 2.1 and earlier allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to (1) a large file, which triggers a long download session without a timeout constraint; or (2) a file with a binary content type, which is downloaded even though it cannot contain usable pingback data.
0
Attacker Value
Unknown
CVE-2007-0389
Disclosure Date: January 19, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in ArsDigita Community System (ACS) 3.4.10 and earlier, and ArsDigita Community Education Solution (ACES) 1.1, allows remote attackers to read arbitrary files via .%252e/ (double-encoded dot dot slash) sequences in the URI.
0
Attacker Value
Unknown
CVE-2006-6369
Disclosure Date: December 07, 2006 (last updated October 04, 2023)
SQL injection vulnerability in lib/entry_reply_entry.php in Invision Community Blog Mod 1.2.4 allows remote attackers to execute arbitrary SQL commands via the eid parameter, when accessed through the "Preview message" functionality.
0
Attacker Value
Unknown
CVE-2006-5881
Disclosure Date: November 14, 2006 (last updated October 04, 2023)
SQL injection vulnerability in cl_CatListing.asp in Dynamic Dataworx NuCommunity 1.0 allows remote attackers to execute arbitrary SQL commands via the cl_cat_ID parameter.
0
Attacker Value
Unknown
CVE-2006-5739
Disclosure Date: November 06, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in cpadmin/cpa_index.php in Leicestershire communityPortals 1.0_2005-10-18_12-31-18 allows remote attackers to execute arbitrary PHP code via a URL in the cp_root_path parameter, a different vector than CVE-2006-5280.
0
Attacker Value
Unknown
CVE-2006-5280
Disclosure Date: October 13, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in includes/import-archive.php in Leicestershire communityPortals 1.0 build 20051018 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cp_root_path parameter.
0
Attacker Value
Unknown
CVE-2006-4869
Disclosure Date: September 19, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in phpunity-postcard.php in phpunity.postcard allows remote attackers to execute arbitrary PHP code via a URL in the gallery_path parameter.
0