Show filters
102 Total Results
Displaying 61-70 of 102
Sort by:
Attacker Value
Unknown
CVE-2006-6157
Disclosure Date: November 28, 2006 (last updated October 04, 2023)
SQL injection vulnerability in index.php in ContentNow 1.39 and earlier allows remote attackers to execute arbitrary SQL commands via the pageid parameter. NOTE: this issue can be leveraged for path disclosure with an invalid pageid parameter.
0
Attacker Value
Unknown
CVE-2006-4989
Disclosure Date: September 26, 2006 (last updated October 04, 2023)
Patrick Michaelis Wili-CMS allows remote attackers to obtain sensitive information via a direct request for (1) thumbnail.php, (2) functions/admin/all.php, (3) functions/admin/init_session.php, (4) functions/all.php, and (5) certain files in example-view/admin_templates/, which reveals the path in various error messages.
0
Attacker Value
Unknown
CVE-2006-4987
Disclosure Date: September 26, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Patrick Michaelis Wili-CMS allow remote attackers to execute arbitrary PHP code via a URL in the globals[content_dir] parameter in (1) example-view/templates/article.php, (2) example-view/templates/root.php, and (3) example-view/templates/dates_list.php.
0
Attacker Value
Unknown
CVE-2006-4988
Disclosure Date: September 26, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Patrick Michaelis Wili-CMS allow remote attackers to inject arbitrary web script or HTML via (1) the query string to relocate.php, (2) the globals[pageid] parameter in example-view/inc/print_button.php, and other unspecified vectors.
0
Attacker Value
Unknown
CVE-2006-2004
Disclosure Date: April 25, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in RI Blog 1.1 allow remote attackers to execute arbitrary SQL command via the (1) username or (2) password fields.
0
Attacker Value
Unknown
CVE-2006-0859
Disclosure Date: February 23, 2006 (last updated February 22, 2025)
Michael Salzer Guestbox 0.6, and other versions before 0.8, allows remote attackers to post an admin comment to a guestbook entry via a certain modified form, possibly related to the nummer parameter.
0
Attacker Value
Unknown
CVE-2006-0861
Disclosure Date: February 23, 2006 (last updated February 22, 2025)
Michael Salzer Guestbox 0.6, and other versions before 0.8, allows remote attackers to obtain the source IP addresses of guestbook entries via a direct request to /gb/gblog.
0
Attacker Value
Unknown
CVE-2006-0860
Disclosure Date: February 23, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Michael Salzer Guestbox 0.6, and other versions before 0.8, allow remote attackers to inject arbitrary web script or HTML via (1) HTML tags that follow a "http://" string, which bypasses a regular expression check, and (2) other unspecified attack vectors.
0
Attacker Value
Unknown
CVE-2005-4775
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Michael Scholz and Sebastian Stein Contineo 2.0, when the admin account lacks an e-mail address attribute, displays the password hash in a warning upon page reload, which might allow remote attackers to view the hash.
0
Attacker Value
Unknown
CVE-2005-0888
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in functions.inc.php for Double Choco Latte 0.9.4.3 allow remote attackers to inject arbitrary web script or HTML via the (1) class or (2) method name.
0