Show filters
530 Total Results
Displaying 361-370 of 530
Sort by:
Attacker Value
Unknown

CVE-2012-4053

Disclosure Date: July 25, 2012 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in eZOE flash player in eZ Publish 4.1 through 4.6 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
0
Attacker Value
Unknown

CVE-2012-2726

Disclosure Date: June 27, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Protest module 6.x-1.x before 6.x-1.2 or 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "administer protest" permission to inject arbitrary web script or HTML via the protest_body parameter.
0
Attacker Value
Unknown

CVE-2012-2907

Disclosure Date: May 21, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the aberdeen_breadcrumb function in template.php in the Aberdeen theme 6.x-1.x before 6.x-1.11 for Drupal, when set to append the content title to the breadcrumb, allows remote attackers to inject arbitrary web script or HTML via the content title in a breadcrumb.
0
Attacker Value
Unknown

CVE-2012-0983

Disclosure Date: February 02, 2012 (last updated October 04, 2023)
SQL injection vulnerability in Scriptsez.net Ez Album allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.
0
Attacker Value
Unknown

CVE-2010-5012

Disclosure Date: November 02, 2011 (last updated October 04, 2023)
SQL injection vulnerability in new.php in DaLogin 2.2 and 2.2.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2010-4889

Disclosure Date: October 07, 2011 (last updated October 04, 2023)
Unspecified vulnerability in the Tiny Market (hm_tinymarket) extension 0.5.4 and earlier for TYPO3 allows attackers to execute arbitrary code via unknown vectors.
0
Attacker Value
Unknown

CVE-2010-4888

Disclosure Date: October 07, 2011 (last updated October 04, 2023)
SQL injection vulnerability in the Tiny Market (hm_tinymarket) extension 0.5.4 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2010-4276

Disclosure Date: December 30, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the lz_tracking_set_sessid function in templates/jscript/jstrack.tpl in LiveZilla 3.2.0.2 allows remote attackers to inject arbitrary web script or HTML via the livezilla parameter in a track action to server.php.
0
Attacker Value
Unknown

CVE-2009-4982

Disclosure Date: August 25, 2010 (last updated October 04, 2023)
SQL injection vulnerability in the select function in Irokez CMS 0.7.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to the default URI.
0
Attacker Value
Unknown

CVE-2010-2672

Disclosure Date: July 08, 2010 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in eZ Publish 3.7.0 through 4.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) SectionID and (2) SearchTimestamp parameters to the search feature and the (3) SearchContentClassAttributeID parameter to the advancedsearch feature.
0