Show filters
105 Total Results
Displaying 71-80 of 105
Sort by:
Attacker Value
Unknown

CVE-2008-5088

Disclosure Date: November 14, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in PHPKB Knowledge Base Software 1.5 Professional allow remote attackers to execute arbitrary SQL commands via the ID parameter to (1) email.php and (2) question.php, a different vector than CVE-2008-1909.
0
Attacker Value
Unknown

CVE-2008-3555

Disclosure Date: August 08, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in (1) WSN Forum 4.1.43 and earlier, (2) Gallery 4.1.30 and earlier, (3) Knowledge Base (WSNKB) 4.1.36 and earlier, (4) Links 4.1.44 and earlier, and possibly (5) Classifieds before 4.1.30 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the TID parameter, as demonstrated by uploading a .jpg file containing PHP sequences.
0
Attacker Value
Unknown

CVE-2008-3100

Disclosure Date: July 29, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in lib/owl.lib.php in Steve Bourgeois and Chris Vincent Owl Intranet Knowledgebase 0.95 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter in a getpasswd action to register.php.
0
Attacker Value
Unknown

CVE-2008-3359

Disclosure Date: July 29, 2008 (last updated October 04, 2023)
SQL injection vulnerability in register.php in Steve Bourgeois and Chris Vincent Owl Intranet Knowledgebase 0.95 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2008-1909

Disclosure Date: April 22, 2008 (last updated October 04, 2023)
SQL injection vulnerability in comment.php in PHP Knowledge Base (PHPKB) 1.5 and 2.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
0
Attacker Value
Unknown

CVE-2008-1726

Disclosure Date: April 11, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in KnowledgeQuest 2.6, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) kqid parameter to (a) articletext.php and (b) articletextonly.php and the (2) username parameter to (c) logincheck.php.
0
Attacker Value
Unknown

CVE-2008-1727

Disclosure Date: April 11, 2008 (last updated October 04, 2023)
KnowledgeQuest 2.5 and 2.6 does not require authentication for access to admincheck.php, which allows remote attackers to create arbitrary admin accounts.
0
Attacker Value
Unknown

CVE-2008-1222

Disclosure Date: March 10, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Dokeos 1.8.4 before SP3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-1223

Disclosure Date: March 10, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Dokeos 1.8.4 before SP3 allows attackers to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown

CVE-2007-6574

Disclosure Date: December 28, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the origin parameter to work/work.php in a display_upload_form action, or the forum parameter to (2) forum/viewforum.php or (3) forum/viewthread.php.
0