Show filters
391 Total Results
Displaying 361-370 of 391
Sort by:
Attacker Value
Unknown

CVE-2006-5096

Disclosure Date: September 29, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in index.php in VirtueMart (formerly known as mambo-phpShop) Joomla! eCommerce Edition CMS 1.0.11, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the Itemid parameter in a (1) com_contact or (2) subscribe action.
0
Attacker Value
Unknown

CVE-2006-5043

Disclosure Date: September 27, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in the Joomlaboard Forum Component (com_joomlaboard) before 1.1.2 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the sbp parameter to (1) file_upload.php or (2) image_upload.php, a variant of CVE-2006-3528.
0
Attacker Value
Unknown

CVE-2006-4996

Disclosure Date: September 26, 2006 (last updated October 04, 2023)
Unspecified vulnerability in JoomlaLib (com_joomlalib) before 1.2.2 for Joomla! allows remote attackers to have an unknown impact, related to "Joomla globals hacked by script kiddies."
0
Attacker Value
Unknown

CVE-2006-4474

Disclosure Date: August 31, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.11 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in (1) Admin Module Manager, (2) Admin Help, and (3) Search.
0
Attacker Value
Unknown

CVE-2006-4469

Disclosure Date: August 31, 2006 (last updated October 04, 2023)
Unspecified vulnerability in PEAR.php in Joomla! before 1.0.11 allows remote attackers to perform "remote execution," related to "Injection Flaws."
0
Attacker Value
Unknown

CVE-2006-4471

Disclosure Date: August 31, 2006 (last updated October 04, 2023)
The Admin Upload Image functionality in Joomla! before 1.0.11 allows remote authenticated users to upload files outside of the /images/stories/ directory via unspecified vectors.
0
Attacker Value
Unknown

CVE-2006-4473

Disclosure Date: August 31, 2006 (last updated October 04, 2023)
Unspecified vulnerability in com_content in Joomla! before 1.0.11, when $mosConfig_hideEmail is set, allows attackers to perform the emailform and emailsend tasks.
0
Attacker Value
Unknown

CVE-2006-4475

Disclosure Date: August 31, 2006 (last updated October 04, 2023)
Joomla! before 1.0.11 does not limit access to the Admin Popups functionality, which has unknown impact and attack vectors.
0
Attacker Value
Unknown

CVE-2006-4472

Disclosure Date: August 31, 2006 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in Joomla! before 1.0.11 allow attackers to bypass user authentication via unknown vectors involving the (1) do_pdf command and the (2) emailform com_content task.
0
Attacker Value
Unknown

CVE-2006-4466

Disclosure Date: August 31, 2006 (last updated October 04, 2023)
Joomla! before 1.0.11 does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to have an unspecified impact. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in Joomla!.
0