Show filters
42 Total Results
Displaying 31-40 of 42
Sort by:
Attacker Value
Unknown
CVE-2006-7025
Disclosure Date: February 23, 2007 (last updated October 04, 2023)
SQL injection vulnerability in admin/config.php in Bookmark4U 2.0 and 2.1 allows remote attackers to inject arbitrary SQL command via the sqlcmd parameter.
0
Attacker Value
Unknown
CVE-2006-6359
Disclosure Date: December 07, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Stefan Frech online-bookmarks 0.6.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2006-6358
Disclosure Date: December 07, 2006 (last updated October 04, 2023)
SQL injection vulnerability in the login function in auth.inc in Stefan Frech online-bookmarks 0.6.12 allows remote attackers to execute arbitrary SQL commands via the (1) username and possibly the (2) password parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2006-6167
Disclosure Date: November 29, 2006 (last updated November 08, 2023)
Multiple PHP remote file inclusion vulnerabilities in L. Brandon Stone and Nathanial P. Hendler Active PHP Bookmarks (APB) 1.1.02 allow remote attackers to execute arbitrary PHP code via a URL in the APB_SETTINGS['apb_path'] parameter in (1) apb_common.php or (2) apb.php. NOTE: CVE and another third party dispute this vulnerability because these PHP scripts exit if the attack vectors are present in GPC variables
0
Attacker Value
Unknown
CVE-2006-4645
Disclosure Date: September 08, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in akarru.gui/main_content.php in Akarru Social BookMarking Engine 0.4.3.34 and earlier, and possibly 0.4.4.120, allows remote attackers to execute arbitrary PHP code via a URL in the bm_content parameter.
0
Attacker Value
Unknown
CVE-2006-2877
Disclosure Date: June 07, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in Bookmark4U 2.0.0 and earlier allows remote attackers to include arbitrary PHP files via the include_prefix parameter in (1) inc/dbase.php, (2) inc/config.php, (3) inc/common.php, and (4) inc/function.php. NOTE: it has been reported that the inc directory is protected by a .htaccess file, so this issue only applies in certain environments or configurations.
0
Attacker Value
Unknown
CVE-2006-1051
Disclosure Date: March 07, 2006 (last updated February 22, 2025)
SQL injection vulnerability in Akarru Social BookMarking Engine before 0.4.3.4 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors, possibly involving the username parameter to akarru.lib/users.php.
0
Attacker Value
Unknown
CVE-2005-0901
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in NukeBookmarks 0.6 for PHP-Nuke allow remote attackers to inject arbitrary web script or HTML via the (1) catname, (2) markname, (3) comment, or (4) category parameter.
0
Attacker Value
Unknown
CVE-2005-0902
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
SQL injection vulnerability in marks.php in NukeBookmarks 0.6 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the category parameter.
0
Attacker Value
Unknown
CVE-2005-0900
Disclosure Date: March 26, 2005 (last updated February 22, 2025)
marks.php in NukeBookmarks 0.6 for PHP-Nuke allows remote attackers to obtain sensitive information via an invalid (1) file or (2) category parameter, which reveal the path in an error message.
0