Show filters
530 Total Results
Displaying 361-370 of 530
Sort by:
Attacker Value
Unknown
CVE-2012-4053
Disclosure Date: July 25, 2012 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in eZOE flash player in eZ Publish 4.1 through 4.6 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
0
Attacker Value
Unknown
CVE-2012-2726
Disclosure Date: June 27, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Protest module 6.x-1.x before 6.x-1.2 or 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "administer protest" permission to inject arbitrary web script or HTML via the protest_body parameter.
0
Attacker Value
Unknown
CVE-2012-2907
Disclosure Date: May 21, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the aberdeen_breadcrumb function in template.php in the Aberdeen theme 6.x-1.x before 6.x-1.11 for Drupal, when set to append the content title to the breadcrumb, allows remote attackers to inject arbitrary web script or HTML via the content title in a breadcrumb.
0
Attacker Value
Unknown
CVE-2012-0983
Disclosure Date: February 02, 2012 (last updated October 04, 2023)
SQL injection vulnerability in Scriptsez.net Ez Album allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.
0
Attacker Value
Unknown
CVE-2010-5012
Disclosure Date: November 02, 2011 (last updated October 04, 2023)
SQL injection vulnerability in new.php in DaLogin 2.2 and 2.2.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2010-4889
Disclosure Date: October 07, 2011 (last updated October 04, 2023)
Unspecified vulnerability in the Tiny Market (hm_tinymarket) extension 0.5.4 and earlier for TYPO3 allows attackers to execute arbitrary code via unknown vectors.
0
Attacker Value
Unknown
CVE-2010-4888
Disclosure Date: October 07, 2011 (last updated October 04, 2023)
SQL injection vulnerability in the Tiny Market (hm_tinymarket) extension 0.5.4 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2010-4276
Disclosure Date: December 30, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the lz_tracking_set_sessid function in templates/jscript/jstrack.tpl in LiveZilla 3.2.0.2 allows remote attackers to inject arbitrary web script or HTML via the livezilla parameter in a track action to server.php.
0
Attacker Value
Unknown
CVE-2009-4982
Disclosure Date: August 25, 2010 (last updated October 04, 2023)
SQL injection vulnerability in the select function in Irokez CMS 0.7.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to the default URI.
0
Attacker Value
Unknown
CVE-2010-2672
Disclosure Date: July 08, 2010 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in eZ Publish 3.7.0 through 4.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) SectionID and (2) SearchTimestamp parameters to the search feature and the (3) SearchContentClassAttributeID parameter to the advancedsearch feature.
0