Show filters
75 Total Results
Displaying 61-70 of 75
Sort by:
Attacker Value
Unknown
CVE-2015-7912
Disclosure Date: November 21, 2015 (last updated October 05, 2023)
The Ice Faces servlet in ag_server_service.exe in the AggreGate Server Service in Tibbo AggreGate before 5.30.06 allows remote attackers to upload and execute arbitrary Java code via a crafted XML document.
0
Attacker Value
Unknown
CVE-2015-4355
Disclosure Date: June 15, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the Watchdog Aggregator module for Drupal allows remote attackers to hijack the authentication of administrators for requests that enable or disable monitoring sites via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-1789
Disclosure Date: March 19, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Kongreg8 1.7.3 allow remote attackers to inject arbitrary web script or HTML via the (1) surname or (2) firstname parameters to modules/members/addmember.php; or (3) groupdescription or (4) groupname parameters to modules/groups/addgroupform.php.
0
Attacker Value
Unknown
CVE-2008-3374
Disclosure Date: July 30, 2008 (last updated October 04, 2023)
SQL injection vulnerability in ajax.php in Gregarius 0.5.4 and earlier allows remote attackers to execute arbitrary SQL commands via the rsargs array parameter in an __exp__getFeedContent action.
0
Attacker Value
Unknown
CVE-2008-3033
Disclosure Date: July 07, 2008 (last updated October 04, 2023)
RSS-aggregator 1.0 does not require administrative authentication for the admin/fonctions/ directory, which allows remote attackers to access admin functions and have unspecified other impact, as demonstrated by (1) an IdFlux request to supprimer_flux.php and (2) a TpsRafraich request to modifier_tps_rafraich.php.
0
Attacker Value
Unknown
CVE-2008-3034
Disclosure Date: July 07, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in RSS-aggregator 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) IdFlux parameter to admin/fonctions/supprimer_flux.php and the (2) IdTag parameter to admin/fonctions/supprimer_tag.php.
0
Attacker Value
Unknown
CVE-2008-3000
Disclosure Date: July 03, 2008 (last updated October 04, 2023)
The Aggregation module 5.x before 5.x-4.4 for Drupal, when node access modules are used, does not properly implement access control, which allows remote attackers to bypass intended restrictions.
0
Attacker Value
Unknown
CVE-2008-2998
Disclosure Date: July 03, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-3001
Disclosure Date: July 03, 2008 (last updated October 04, 2023)
The Aggregation module 5.x before 5.x-4.4 for Drupal allows remote attackers to upload files with arbitrary extensions, and possibly execute arbitrary code, via a crafted feed that allows upload of files with arbitrary extensions.
0
Attacker Value
Unknown
CVE-2008-2999
Disclosure Date: July 03, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
0