Show filters
59 Total Results
Displaying 51-59 of 59
Sort by:
Attacker Value
Unknown
CVE-2008-3572
Disclosure Date: August 10, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in Pligg 9.9.5 allows remote attackers to inject arbitrary web script or HTML via the category parameter.
0
Attacker Value
Unknown
CVE-2008-3573
Disclosure Date: August 10, 2008 (last updated October 04, 2023)
The CAPTCHA implementation in (1) Pligg 9.9.5 and possibly (2) Francisco Burzi PHP-Nuke 8.1 provides a critical random number (the ts_random value) within the URL in the SRC attribute of an IMG element, which allows remote attackers to pass the CAPTCHA test via a calculation that combines this value with the current date and the HTTP User-Agent string.
0
Attacker Value
Unknown
CVE-2008-3366
Disclosure Date: July 30, 2008 (last updated October 04, 2023)
SQL injection vulnerability in story.php in Pligg CMS Beta 9.9.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this might overlap CVE-2008-1774.
0
Attacker Value
Unknown
CVE-2008-1774
Disclosure Date: April 14, 2008 (last updated October 04, 2023)
SQL injection vulnerability in editlink.php in Pligg 9.9.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown
CVE-2007-5579
Disclosure Date: October 18, 2007 (last updated October 04, 2023)
login.php in Pligg CMS 9.5 uses a guessable confirmation code when resetting a forgotten password, which allows remote attackers with knowledge of a username to reset that user's password by calculating the confirmationcode parameter.
0
Attacker Value
Unknown
CVE-2006-7119
Disclosure Date: March 06, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in kernel/system/startup.php in J. He PHPGiggle 12.08 and earlier, as distributed on comscripts.com, allows remote attackers to execute arbitrary PHP code via a URL in the CFG_PHPGIGGLE_ROOT parameter.
0
Attacker Value
Unknown
CVE-2007-0116
Disclosure Date: January 09, 2007 (last updated October 04, 2023)
Digger Solutions Intranet Open Source (IOS) stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for data/intranet.mdb.
0
Attacker Value
Unknown
CVE-2006-0692
Disclosure Date: February 15, 2006 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in Carey Briggs PHP/MYSQL Timesheet 1 and 2 allow remote attackers to execute arbitrary SQL commands via the (1) yr, (2) month, (3) day, and (4) job parameters in (a) index.php and (b) changehrs.php.
0
Attacker Value
Unknown
CVE-2005-4656
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
SQL injection vulnerability in index.php in TClanPortal 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands, and retrieve all usernames and passwords, via the id parameter.
0