Show filters
87 Total Results
Displaying 41-50 of 87
Sort by:
Attacker Value
Unknown
CVE-2008-0653
Disclosure Date: February 07, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the Ynews (com_ynews) 1.0.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showYNews action.
0
Attacker Value
Unknown
CVE-2007-6541
Disclosure Date: December 27, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in neuron news 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the topic parameter in a viewtopic action, or the (2) newsyear or (3) newsmonth parameter in a newsarchive action to the default URI in patch/.
0
Attacker Value
Unknown
CVE-2007-6540
Disclosure Date: December 27, 2007 (last updated October 04, 2023)
SQL injection vulnerability in neuron news 1.0 allows remote attackers to execute arbitrary SQL commands via the q parameter to the default URI in patch/.
0
Attacker Value
Unknown
CVE-2007-5050
Disclosure Date: September 24, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in Neuron News 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the q parameter.
0
Attacker Value
Unknown
CVE-2007-4603
Disclosure Date: August 31, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in index.php in ACG News 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the aid parameter in a showarticle action or (2) the catid parameter in a showcat action.
0
Attacker Value
Unknown
CVE-2007-2598
Disclosure Date: May 11, 2007 (last updated October 04, 2023)
SQL injection vulnerability in print.php in SimpleNews 1.0.0 FINAL allows remote attackers to execute arbitrary SQL commands via the news_id parameter.
0
Attacker Value
Unknown
CVE-2007-2303
Disclosure Date: April 26, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in includes/footer.php in News Manager Deluxe (NMDeluxe) 1.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the template parameter.
0
Attacker Value
Unknown
CVE-2007-1438
Disclosure Date: March 13, 2007 (last updated October 04, 2023)
SQL injection vulnerability in devami.asp in X-Ice News System 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown
CVE-2007-1248
Disclosure Date: March 03, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in built2go News Manager Blog 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) cid, (2) uid, and (3) nid parameters to (a) news.php, and the nid parameter to (b) rating.php.
0
Attacker Value
Unknown
CVE-2006-7081
Disclosure Date: March 02, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in PhpNews 1.0 allow remote attackers to execute arbitrary PHP code via the Include parameter to (1) Include/lib.inc.php3 and (2) Include/variables.php3.
0