Show filters
391 Total Results
Displaying 331-340 of 391
Sort by:
Attacker Value
Unknown

CVE-2007-5065

Disclosure Date: September 24, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in admin.slideshow1.php in the Flash Slide Show (com_slideshow) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.
0
Attacker Value
Unknown

CVE-2007-4923

Disclosure Date: September 17, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in admin.joomlaradiov5.php in the Joomla Radio 5 (com_joomlaradiov5) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.
0
Attacker Value
Unknown

CVE-2007-4817

Disclosure Date: September 11, 2007 (last updated October 04, 2023)
Unrestricted file upload vulnerability in the Restaurante (com_restaurante) component for Joomla! allows remote attackers to upload and execute arbitrary PHP code via an upload action specifying a filename with a double extension such as .php.jpg, which creates an accessible file under img_original/.
0
Attacker Value
Unknown

CVE-2007-4777

Disclosure Date: September 10, 2007 (last updated October 04, 2023)
SQL injection vulnerability in Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to execute arbitrary SQL commands via unspecified vectors, probably related to the archive section. NOTE: this may be the same as CVE-2007-4778.
0
Attacker Value
Unknown

CVE-2007-4778

Disclosure Date: September 10, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in the content component (com_content) in Joomla! 1.5 Beta1, Beta2, and RC1 allow remote attackers to execute arbitrary SQL commands via the filter parameter in an archive action to (1) archive.php, (2) category.php, or (3) section.php in models/. NOTE: this may be the same as CVE-2007-4777.
0
Attacker Value
Unknown

CVE-2007-4780

Disclosure Date: September 10, 2007 (last updated October 04, 2023)
Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to obtain sensitive information (the full path) via unspecified vectors, probably involving direct requests to certain PHP scripts in tmpl/ directories.
0
Attacker Value
Unknown

CVE-2007-4779

Disclosure Date: September 10, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably related to the archive section.
0
Attacker Value
Unknown

CVE-2007-4781

Disclosure Date: September 10, 2007 (last updated October 04, 2023)
administrator/index.php in the installer component (com_installer) in Joomla! 1.5 Beta1, Beta2, and RC1 allows remote authenticated administrators to upload arbitrary files to tmp/ via the "Upload Package File" functionality, which is accessible when com_installer is the value of the option parameter.
0
Attacker Value
Unknown

CVE-2007-4190

Disclosure Date: August 08, 2007 (last updated October 04, 2023)
CRLF injection vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to inject arbitrary HTTP headers and probably conduct HTTP response splitting attacks via CRLF sequences in the url parameter. NOTE: this can be leveraged for cross-site scripting (XSS) attacks. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2007-4185

Disclosure Date: August 08, 2007 (last updated October 04, 2023)
Joomla! 1.0.12 allows remote attackers to obtain sensitive information via a direct request for (1) Stat.php (2) OutputFilter.php, (3) OutputCache.php, (4) Modifier.php, (5) Reader.php, and (6) TemplateCache.php in includes/patTemplate/patTemplate/; (7) includes/Cache/Lite/Output.php; and other unspecified components, which reveal the path in various error messages.
0