Show filters
98 Total Results
Displaying 51-60 of 98
Sort by:
Attacker Value
Unknown

CVE-2007-3221

Disclosure Date: June 14, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.
0
Attacker Value
Unknown

CVE-2007-3222

Disclosure Date: June 14, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in modify.php in the XFsection 1.07 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the dir_module parameter.
0
Attacker Value
Unknown

CVE-2007-3057

Disclosure Date: June 06, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in include/wysiwyg/spaw_control.class.php in the icontent 4.5 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.
0
Attacker Value
Unknown

CVE-2007-2738

Disclosure Date: May 17, 2007 (last updated October 04, 2023)
SQL injection vulnerability in glossaire-p-f.php in the Glossaire 1.7 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the sid parameter in an ImprDef action.
0
Attacker Value
Unknown

CVE-2007-2737

Disclosure Date: May 17, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the MyConference 1.0 module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2007-2571

Disclosure Date: May 09, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the wfquotes 1.0 0 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the c parameter in a cat action.
0
Attacker Value
Unknown

CVE-2007-2543

Disclosure Date: May 09, 2007 (last updated October 04, 2023)
SQL injection vulnerability in game.php in the Flashgames 1.0.1 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the lid parameter.
0
Attacker Value
Unknown

CVE-2007-2370

Disclosure Date: April 30, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the John Mordo Jobs 2.4 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a jobsview action. NOTE: the module name was originally reported as Job Listings.
0
Attacker Value
Unknown

CVE-2007-2091

Disclosure Date: April 18, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in blocks/tsdisplay4xoops_block2.php in tsdisplay4xoops (TSD4XOOPS, aka the TeamSpeak display module) 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the xoops_url parameter.
0
Attacker Value
Unknown

CVE-2007-1979

Disclosure Date: April 12, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the PopnupBlog 2.52 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the postid parameter, possibly involving the get_blogid_from_postid function in class/PopnupBlogUtils.php. NOTE: later versions such as 3.03 and 3.05 might also be affected.
0