Show filters
64 Total Results
Displaying 61-64 of 64
Sort by:
Attacker Value
Unknown

CVE-2007-6127

Disclosure Date: November 26, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in project alumni 1.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the year parameter to (1) view.page.inc.php, which is reachable through a view action to index.php; or (2) the year parameter to news.page.inc.php, which is reachable through a news action to index.php.
0
Attacker Value
Unknown

CVE-2007-6126

Disclosure Date: November 26, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in project alumni 1.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the year parameter to (1) xml/index.php; or (2) the year parameter to view.page.inc.php, which is reachable through a view action to the top-level index.php.
0
Attacker Value
Unknown

CVE-2006-5529

Disclosure Date: October 26, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in smumdadotcom_ascyb_alumni/mod.php in SchoolAlumni Portal 2.26 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search operation in the katalog module. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2006-5528

Disclosure Date: October 26, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in mod.php in SchoolAlumni Portal 2.26 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod parameter. NOTE: some of these details are obtained from third party information.
0