Show filters
53 Total Results
Displaying 51-53 of 53
Sort by:
Attacker Value
Unknown

CVE-2008-5221

Disclosure Date: November 25, 2008 (last updated October 04, 2023)
The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified password and password_retype parameters.
0
Attacker Value
Unknown

CVE-2008-2228

Disclosure Date: May 14, 2008 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in portfolio/commentaires/derniers_commentaires.php in Cyberfolio 7.12, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the rep parameter.
0
Attacker Value
Unknown

CVE-2006-5768

Disclosure Date: November 06, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Cyberfolio 2.0 RC1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the av parameter to (1) msg/view.php, (2) msg/inc_message.php, (3) msg/inc_envoi.php, and (4) admin/incl_voir_compet.php.
0