Show filters
735 Total Results
Displaying 651-660 of 735
Sort by:
Attacker Value
Unknown

CVE-2008-1066

Disclosure Date: February 28, 2008 (last updated October 04, 2023)
The modifier.regex_replace.php plugin in Smarty before 2.6.19, as used by Serendipity (S9Y) and other products, allows attackers to call arbitrary PHP functions via templates, related to a '\0' character in a search string.
0
Attacker Value
Unknown

CVE-2008-0872

Disclosure Date: February 21, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in SmarterTools SmarterMail Enterprise 4.3 allows remote attackers to inject arbitrary web script or HTML via a STYLE attribute of an element in the Subject field of an e-mail message.
0
Attacker Value
Unknown

CVE-2008-0688

Disclosure Date: February 12, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in catalog.php in Smartscript Domain Trader 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a viewcategory action.
0
Attacker Value
Unknown

CVE-2008-0442

Disclosure Date: January 25, 2008 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the ffile parameter, a different vector than CVE-2008-0376. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2008-0147

Disclosure Date: January 09, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in SmallNuke 2.0.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via (1) the user_email parameter and possibly (2) username parameter in a Members action.
0
Attacker Value
Unknown

CVE-2007-6656

Disclosure Date: January 04, 2008 (last updated October 04, 2023)
SQL injection vulnerability in content_css.php in the TinyMCE module for CMS Made Simple 1.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the templateid parameter.
0
Attacker Value
Unknown

CVE-2007-5725

Disclosure Date: October 30, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Smart-Shop allow remote attackers to inject arbitrary web script or HTML via (1) the email parameter to index.php; or the command parameter to index.php in (2) the default action for the home page, (3) a currencies action, or (4) a basket action.
0
Attacker Value
Unknown

CVE-2007-5442

Disclosure Date: October 14, 2007 (last updated October 04, 2023)
CMS Made Simple 1.1.3.1 does not check the permissions assigned to users who attempt uploads, which allows remote authenticated users to upload unspecified files via unknown vectors.
0
Attacker Value
Unknown

CVE-2007-5443

Disclosure Date: October 14, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple 1.1.3.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) the anchor tag and (2) listtags.
0
Attacker Value
Unknown

CVE-2007-5441

Disclosure Date: October 14, 2007 (last updated October 04, 2023)
CMS Made Simple 1.1.3.1 does not check the permissions assigned to users in some situations, which allows remote authenticated users to perform some administrative actions, as demonstrated by (1) adding a user via a direct request to admin/adduser.php and (2) reading the admin log via an "admin/adminlog.php?page=1" request.
0