Show filters
391 Total Results
Displaying 341-350 of 391
Sort by:
Attacker Value
Unknown
CVE-2007-4188
Disclosure Date: August 08, 2007 (last updated October 04, 2023)
Session fixation vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to hijack administrative web sessions via unspecified vectors.
0
Attacker Value
Unknown
CVE-2007-4187
Disclosure Date: August 08, 2007 (last updated October 04, 2023)
Multiple eval injection vulnerabilities in the com_search component in Joomla! 1.5 beta before RC1 (aka Mapya) allow remote attackers to execute arbitrary PHP code via PHP sequences in the searchword parameter, related to default_results.php in (1) components/com_search/views/search/tmpl/ and (2) templates/beez/html/com_search/search/.
0
Attacker Value
Unknown
CVE-2007-4189
Disclosure Date: August 08, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.13 (aka Sunglow) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in the (1) com_search, (2) com_content, and (3) mod_login components. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2007-4184
Disclosure Date: August 08, 2007 (last updated October 04, 2023)
SQL injection vulnerability in administrator/popups/pollwindow.php in Joomla! 1.0.12 allows remote attackers to execute arbitrary SQL commands via the pollid parameter.
0
Attacker Value
Unknown
CVE-2007-2199
Disclosure Date: April 24, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vincent Blavet PhpConcept Library, as used in multiple products including (1) Joomla! 1.5.0 Beta, (2) N/X Web Content Management System (WCMS) 4.5, (3) CJG EXPLORER PRO 3.3, and (4) phpSiteBackup 0.1, allows remote attackers to execute arbitrary PHP code via a URL in the g_pcltar_lib_dir parameter.
0
Attacker Value
Unknown
CVE-2007-2144
Disclosure Date: April 19, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in includes/CAltInstaller.php in the JoomlaPack (com_jpack) 1.0.4a2 RE component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
0
Attacker Value
Unknown
CVE-2007-2143
Disclosure Date: April 19, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in index.php in the Be2004-2 template for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
0
Attacker Value
Unknown
CVE-2006-7009
Disclosure Date: February 12, 2007 (last updated October 04, 2023)
Joomla! before 1.0.10 allows remote attackers to spoof the frontend submission forms, which has unknown impact and attack vectors.
0
Attacker Value
Unknown
CVE-2006-7010
Disclosure Date: February 12, 2007 (last updated October 04, 2023)
The mosgetparam implementation in Joomla! before 1.0.10, does not set a variable's data type to integer when the variable's default value is numeric, which has unspecified impact and attack vectors, which may permit SQL injection attacks.
0
Attacker Value
Unknown
CVE-2006-7008
Disclosure Date: February 12, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Joomla! before 1.0.10 has unknown impact and attack vectors, related to "securing mosmsg from misuse." NOTE: it is possible that this issue overlaps CVE-2006-1029.
0