Show filters
95 Total Results
Displaying 61-70 of 95
Sort by:
Attacker Value
Unknown

CVE-2012-1252

Disclosure Date: June 04, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in RSSOwl before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via a feed, a different vulnerability than CVE-2006-4760.
0
Attacker Value
Unknown

CVE-2010-2725

Disclosure Date: August 05, 2010 (last updated October 04, 2023)
BarnOwl before 1.6.2 does not check the return code of calls to the (1) ZPending and (2) ZReceiveNotice functions in libzephyr, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.
0
Attacker Value
Unknown

CVE-2010-2122

Disclosure Date: June 01, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in the SimpleDownload (com_simpledownload) component before 0.9.6 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
0
Attacker Value
Unknown

CVE-2010-0793

Disclosure Date: March 16, 2010 (last updated October 04, 2023)
Buffer overflow in BarnOwl before 1.5.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted CC: header.
0
Attacker Value
Unknown

CVE-2009-3916

Disclosure Date: November 09, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Node Hierarchy module 5.x before 5.x-1.3 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a child node title.
0
Attacker Value
Unknown

CVE-2009-0363

Disclosure Date: February 17, 2009 (last updated October 04, 2023)
Multiple buffer overflows in (a) BarnOwl before 1.0.5 and (b) owl 2.1.11 allow remote attackers to execute arbitrary code via vectors involving (1) a crafted zcrypt message, related to zcrypt.c; (2) a reply command on a message with a Zephyr Cc: list, related to zwrite.c; and unspecified other use of the products.
0
Attacker Value
Unknown

CVE-2008-5858

Disclosure Date: January 06, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in KnowledgeTree before 3.5.4a allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2007-4281.
0
Attacker Value
Unknown

CVE-2008-5857

Disclosure Date: January 06, 2009 (last updated October 04, 2023)
The DropDocuments plugin in KnowledgeTree before 3.5.4a allows remote authenticated users to gain administrative privileges via a certain sequence of "browse documents" and dashboard requests.
0
Attacker Value
Unknown

CVE-2008-5088

Disclosure Date: November 14, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in PHPKB Knowledge Base Software 1.5 Professional allow remote attackers to execute arbitrary SQL commands via the ID parameter to (1) email.php and (2) question.php, a different vector than CVE-2008-1909.
0
Attacker Value
Unknown

CVE-2008-3100

Disclosure Date: July 29, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in lib/owl.lib.php in Steve Bourgeois and Chris Vincent Owl Intranet Knowledgebase 0.95 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter in a getpasswd action to register.php.
0