Show filters
87 Total Results
Displaying 31-40 of 87
Sort by:
Attacker Value
Unknown
CVE-2008-7037
Disclosure Date: August 24, 2009 (last updated October 04, 2023)
The Sidebar gadget in ITN News Gadget (aka ITN Hub Gadget) 1.06 for Windows Vista, and possibly other versions before 1.23, allows remote web servers or man-in-the-middle attackers to execute arbitrary commands via script in a short_title response.
0
Attacker Value
Unknown
CVE-2009-2735
Disclosure Date: August 11, 2009 (last updated October 04, 2023)
SQL injection vulnerability in admin.php in sun-jester OpenNews 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.
0
Attacker Value
Unknown
CVE-2009-2736
Disclosure Date: August 11, 2009 (last updated October 04, 2023)
Static code injection vulnerability in admin.php in sun-jester OpenNews 1.0 allows remote authenticated administrators to inject arbitrary PHP code into config.php via the "Overall Width" field in a setconfig action.
0
Attacker Value
Unknown
CVE-2008-6855
Disclosure Date: July 14, 2009 (last updated October 04, 2023)
Xigla Software Absolute News Feed 1.0 and possibly 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a certain cookie.
0
Attacker Value
Unknown
CVE-2009-0722
Disclosure Date: February 24, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in admin.php in Potato News 1.0.0 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the user cookie parameter.
0
Attacker Value
Unknown
CVE-2009-0643
Disclosure Date: February 20, 2009 (last updated October 04, 2023)
Static code injection vulnerability in post.php in Simple PHP News 1.0 final allows remote attackers to inject arbitrary PHP code into news.txt via the post parameter, and then execute the code via a direct request to display.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2009-0610
Disclosure Date: February 17, 2009 (last updated October 04, 2023)
Multiple static code injection vulnerabilities in post.php in Simple PHP News 1.0 final allow remote attackers to inject arbitrary PHP code into news.txt via the (1) title or (2) date parameter, and then execute the code via a direct request to display.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2008-5996
Disclosure Date: January 28, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Simplenews module 5.x before 5.x-1.5 and 6.x before 6.x-1.0-beta4, a module for Drupal, allows remote authenticated users, with "administer taxonomy" permissions, to inject arbitrary web script or HTML via a Newsletter category field.
0
Attacker Value
Unknown
CVE-2008-4622
Disclosure Date: October 21, 2008 (last updated October 04, 2023)
The isLoggedIn function in fastnews-code.php in phpFastNews 1.0.0 allows remote attackers to bypass authentication and gain administrative access by setting the fn-loggedin cookie to 1.
0
Attacker Value
Unknown
CVE-2008-2219
Disclosure Date: May 14, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in install.php in C-News.fr C-News 1.0.1 allows remote attackers to inject arbitrary web script or HTML via the etape parameter.
0