Show filters
51 Total Results
Displaying 41-50 of 51
Sort by:
Attacker Value
Unknown
CVE-2013-2618
Disclosure Date: June 05, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in editor.php in Network Weathermap before 0.97b allows remote attackers to inject arbitrary web script or HTML via the map_title parameter.
0
Attacker Value
Unknown
CVE-2013-3739
Disclosure Date: June 05, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in editor.php in Network Weathermap 0.97c and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the mapname parameter in a show_config action.
0
Attacker Value
Unknown
CVE-2012-5187
Disclosure Date: February 06, 2013 (last updated October 05, 2023)
The Weathernews Touch application 2.3.2 and earlier for Android allows attackers to obtain sensitive information about logged locations via a crafted application that leverages read permission for system log files.
0
Attacker Value
Unknown
CVE-2008-5770
Disclosure Date: December 30, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in config/make_config.php in PHP Weather 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
0
Attacker Value
Unknown
CVE-2008-5771
Disclosure Date: December 30, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in test.php in PHP Weather 2.2.2 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the language parameter.
0
Attacker Value
Unknown
CVE-2008-1348
Disclosure Date: March 17, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in the eWebsite eWeather (Weather) module for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the chart parameter to modules.php.
0
Attacker Value
Unknown
CVE-2007-5674
Disclosure Date: October 24, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in InstaGuide Weather (aka Weather for PHP) 1.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PageName parameter.
0
Attacker Value
Unknown
CVE-2007-2044
Disclosure Date: April 16, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in mod_weather.php in the Antonis Ventouris Weather module for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter.
0
Attacker Value
Unknown
CVE-2006-5519
Disclosure Date: October 26, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in Savant2/Savant2_Plugin_options.php in the MambWeather 1.8.1 and earlier component for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
0
Attacker Value
Unknown
CVE-2006-5185
Disclosure Date: October 10, 2006 (last updated October 04, 2023)
Eval injection vulnerability in Template.php in HAMweather 3.9.8.4 and earlier allows remote attackers to execute arbitrary code via a modified query string, which is supplied to an eval function call within the do_parse_code function.
0