Show filters
95 Total Results
Displaying 61-70 of 95
Sort by:
Attacker Value
Unknown
CVE-2012-1252
Disclosure Date: June 04, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in RSSOwl before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via a feed, a different vulnerability than CVE-2006-4760.
0
Attacker Value
Unknown
CVE-2010-2725
Disclosure Date: August 05, 2010 (last updated October 04, 2023)
BarnOwl before 1.6.2 does not check the return code of calls to the (1) ZPending and (2) ZReceiveNotice functions in libzephyr, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.
0
Attacker Value
Unknown
CVE-2010-2122
Disclosure Date: June 01, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in the SimpleDownload (com_simpledownload) component before 0.9.6 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
0
Attacker Value
Unknown
CVE-2010-0793
Disclosure Date: March 16, 2010 (last updated October 04, 2023)
Buffer overflow in BarnOwl before 1.5.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted CC: header.
0
Attacker Value
Unknown
CVE-2009-3916
Disclosure Date: November 09, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Node Hierarchy module 5.x before 5.x-1.3 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a child node title.
0
Attacker Value
Unknown
CVE-2009-0363
Disclosure Date: February 17, 2009 (last updated October 04, 2023)
Multiple buffer overflows in (a) BarnOwl before 1.0.5 and (b) owl 2.1.11 allow remote attackers to execute arbitrary code via vectors involving (1) a crafted zcrypt message, related to zcrypt.c; (2) a reply command on a message with a Zephyr Cc: list, related to zwrite.c; and unspecified other use of the products.
0
Attacker Value
Unknown
CVE-2008-5858
Disclosure Date: January 06, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in KnowledgeTree before 3.5.4a allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2007-4281.
0
Attacker Value
Unknown
CVE-2008-5857
Disclosure Date: January 06, 2009 (last updated October 04, 2023)
The DropDocuments plugin in KnowledgeTree before 3.5.4a allows remote authenticated users to gain administrative privileges via a certain sequence of "browse documents" and dashboard requests.
0
Attacker Value
Unknown
CVE-2008-5088
Disclosure Date: November 14, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in PHPKB Knowledge Base Software 1.5 Professional allow remote attackers to execute arbitrary SQL commands via the ID parameter to (1) email.php and (2) question.php, a different vector than CVE-2008-1909.
0
Attacker Value
Unknown
CVE-2008-3100
Disclosure Date: July 29, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in lib/owl.lib.php in Steve Bourgeois and Chris Vincent Owl Intranet Knowledgebase 0.95 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter in a getpasswd action to register.php.
0