Show filters
39 Total Results
Displaying 31-39 of 39
Sort by:
Attacker Value
Unknown

CVE-2006-4069

Disclosure Date: August 10, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Elaine Aquino Online Zone Journals (OZJournals) 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) m and (2) c parameters in index.php, (3) a search action, and (4) a "submit comment" action.
0
Attacker Value
Unknown

CVE-2006-2390

Disclosure Date: May 16, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in OZJournals 1.2 allows remote attackers to inject arbitrary web script or HTML via the vname parameter in the comments functionality.
0
Attacker Value
Unknown

CVE-2006-0066

Disclosure Date: January 03, 2006 (last updated February 22, 2025)
SQL injection vulnerability in index.php in PHPjournaler 1.0 allows remote attackers to execute arbitrary SQL commands via the readold parameter.
0
Attacker Value
Unknown

CVE-2005-4606

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
SQL injection vulnerability in check_user.asp in multiple Web Wiz products including (1) Site News 3.06 and earlier, (2) Journal 1.0 and earlier, (3) Polls 3.06 and earlier, and (4) and Database Login 1.71 and earlier allows remote attackers to execute arbitrary SQL commands via the txtUserName parameter.
0
Attacker Value
Unknown

CVE-2005-4455

Disclosure Date: December 21, 2005 (last updated February 22, 2025)
cleanhtml.pl 1.129 in LiveJournal CVS before Dec 13 2005 allows remote attackers to inject scripting languages via the XSL namespace in XML, via vectors such as customview.cgi.
0
Attacker Value
Unknown

CVE-2005-4454

Disclosure Date: December 21, 2005 (last updated February 22, 2025)
Validate-before-filter vulnerability in cleanhtml.pl 1.129 in LiveJournal CVS before Dec 7 2005, when the cleancss option is enabled, allows remote attackers to conduct cross-site scripting (XSS) attacks via a "\" (backslash) within a "javascript" scheme in a style property (such as "javas\cript"), which bypasses the "javascript" check before the "\" is stripped and then rendered in web browsers that allow scripting in style sheets.
0
Attacker Value
Unknown

CVE-2004-2639

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Unspecified vulnerability in Journalness 3.0.7 and earlier allows remote attackers to create or modify posts via unknown attack vectors.
0
Attacker Value
Unknown

CVE-2004-0261

Disclosure Date: November 23, 2004 (last updated February 22, 2025)
oj.cgi in OpenJournal 2.0 through 2.0.5 allows remote attackers to bypass authentication and access the control panel via a 0 in the uid parameter.
0
Attacker Value
Unknown

CVE-2004-0310

Disclosure Date: November 23, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in LiveJournal 1.0 and 1.1 allows remote attackers to execute Javascript as other users via the stylesheet, which does not strip the semicolon or parentheses, as demonstrated using a background:url.
0