Show filters
98 Total Results
Displaying 41-50 of 98
Sort by:
Attacker Value
Unknown
CVE-2007-6675
Disclosure Date: January 08, 2008 (last updated October 04, 2023)
The b_system_comments_show function in htdocs/modules/system/blocks/system_blocks.php in XOOPS before 2.0.18 does not check permissions, which allows remote attackers to read the comments in restricted modules.
0
Attacker Value
Unknown
CVE-2008-0138
Disclosure Date: January 08, 2008 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in xoopsgallery/init_basic.php in the mod_gallery module for XOOPS, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter.
0
Attacker Value
Unknown
CVE-2007-6380
Disclosure Date: December 15, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in e-Xoops (exoops) 1.08, and 1.05 Rev 1 through 3, allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to (a) mylinks/ratelink.php, (b) adresses/ratefile.php, (c) mydownloads/ratefile.php, (d) mysections/ratefile.php, and (e) myalbum/ratephoto.php in modules/; the (2) bid parameter to (f) modules/banners/click.php; and the (3) gid parameter to (g) modules/arcade/index.php in a show_stats and play_game action, related issues to CVE-2007-5104 and CVE-2007-6266.
0
Attacker Value
Unknown
CVE-2007-5978
Disclosure Date: November 15, 2007 (last updated October 04, 2023)
SQL injection vulnerability in brokenlink.php in the mylinks module for XOOPS allows remote attackers to execute arbitrary SQL commands via the lid parameter.
0
Attacker Value
Unknown
CVE-2007-5188
Disclosure Date: October 03, 2007 (last updated October 04, 2023)
Unspecified vulnerability in the XOOPS uploader class in Xoops 2.0.17.1-RC1 and earlier allows remote attackers to upload arbitrary files via unspecified vectors related to improper upload configuration settings in class/uploader.php and class/mimetypes.inc.php, possibly an incomplete blacklist that omits the .php4 extension.
0
Attacker Value
Unknown
CVE-2007-3311
Disclosure Date: June 21, 2007 (last updated October 04, 2023)
SQL injection vulnerability in print.php in the Articles 1.02 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown
CVE-2007-3289
Disclosure Date: June 20, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.
0
Attacker Value
Unknown
CVE-2007-3237
Disclosure Date: June 15, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.
0
Attacker Value
Unknown
CVE-2007-3236
Disclosure Date: June 15, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the xoopsConfig[root_path] parameter.
0
Attacker Value
Unknown
CVE-2007-3220
Disclosure Date: June 14, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in admin/editor2/spaw_control.class.php in the Cjay Content 3 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this may be a duplicate of CVE-2006-4656.
0