Show filters
87 Total Results
Displaying 31-40 of 87
Sort by:
Attacker Value
Unknown

CVE-2008-7037

Disclosure Date: August 24, 2009 (last updated October 04, 2023)
The Sidebar gadget in ITN News Gadget (aka ITN Hub Gadget) 1.06 for Windows Vista, and possibly other versions before 1.23, allows remote web servers or man-in-the-middle attackers to execute arbitrary commands via script in a short_title response.
0
Attacker Value
Unknown

CVE-2009-2735

Disclosure Date: August 11, 2009 (last updated October 04, 2023)
SQL injection vulnerability in admin.php in sun-jester OpenNews 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.
0
Attacker Value
Unknown

CVE-2009-2736

Disclosure Date: August 11, 2009 (last updated October 04, 2023)
Static code injection vulnerability in admin.php in sun-jester OpenNews 1.0 allows remote authenticated administrators to inject arbitrary PHP code into config.php via the "Overall Width" field in a setconfig action.
0
Attacker Value
Unknown

CVE-2008-6855

Disclosure Date: July 14, 2009 (last updated October 04, 2023)
Xigla Software Absolute News Feed 1.0 and possibly 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a certain cookie.
0
Attacker Value
Unknown

CVE-2009-0722

Disclosure Date: February 24, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in admin.php in Potato News 1.0.0 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the user cookie parameter.
0
Attacker Value
Unknown

CVE-2009-0643

Disclosure Date: February 20, 2009 (last updated October 04, 2023)
Static code injection vulnerability in post.php in Simple PHP News 1.0 final allows remote attackers to inject arbitrary PHP code into news.txt via the post parameter, and then execute the code via a direct request to display.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2009-0610

Disclosure Date: February 17, 2009 (last updated October 04, 2023)
Multiple static code injection vulnerabilities in post.php in Simple PHP News 1.0 final allow remote attackers to inject arbitrary PHP code into news.txt via the (1) title or (2) date parameter, and then execute the code via a direct request to display.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2008-5996

Disclosure Date: January 28, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Simplenews module 5.x before 5.x-1.5 and 6.x before 6.x-1.0-beta4, a module for Drupal, allows remote authenticated users, with "administer taxonomy" permissions, to inject arbitrary web script or HTML via a Newsletter category field.
0
Attacker Value
Unknown

CVE-2008-4622

Disclosure Date: October 21, 2008 (last updated October 04, 2023)
The isLoggedIn function in fastnews-code.php in phpFastNews 1.0.0 allows remote attackers to bypass authentication and gain administrative access by setting the fn-loggedin cookie to 1.
0
Attacker Value
Unknown

CVE-2008-2219

Disclosure Date: May 14, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in install.php in C-News.fr C-News 1.0.1 allows remote attackers to inject arbitrary web script or HTML via the etape parameter.
0