Show filters
95 Total Results
Displaying 71-80 of 95
Sort by:
Attacker Value
Unknown
CVE-2008-3359
Disclosure Date: July 29, 2008 (last updated October 04, 2023)
SQL injection vulnerability in register.php in Steve Bourgeois and Chris Vincent Owl Intranet Knowledgebase 0.95 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2008-1726
Disclosure Date: April 11, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in KnowledgeQuest 2.6, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) kqid parameter to (a) articletext.php and (b) articletextonly.php and the (2) username parameter to (c) logincheck.php.
0
Attacker Value
Unknown
CVE-2008-1727
Disclosure Date: April 11, 2008 (last updated October 04, 2023)
KnowledgeQuest 2.5 and 2.6 does not require authentication for access to admincheck.php, which allows remote attackers to create arbitrary admin accounts.
0
Attacker Value
Unknown
CVE-2007-6632
Disclosure Date: January 04, 2008 (last updated October 04, 2023)
showCode.php in xml2owl 0.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter.
0
Attacker Value
Unknown
CVE-2007-6322
Disclosure Date: December 13, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in filedownload.php in xml2owl 0.1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
0
Attacker Value
Unknown
CVE-2007-4281
Disclosure Date: August 09, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in KnowledgeTree Open Source 3.4 and 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the login field on the login page, and other unspecified vectors.
0
Attacker Value
Unknown
CVE-2007-3371
Disclosure Date: June 22, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in plugins/widgets/htmledit/htmledit.php in Powl 0.94 allows remote attackers to execute arbitrary PHP code via a URL in the _POWL[installPath] parameter.
0
Attacker Value
Unknown
CVE-2007-2849
Disclosure Date: May 24, 2007 (last updated October 04, 2023)
KnowledgeTree Document Management (aka KnowledgeTree Open Source) before STABLE 3.3.7 does not require a password for an unregistered user, when the user exists in Active Directory, which allows remote attackers to log onto KTDMS without the intended authorization check.
0
Attacker Value
Unknown
CVE-2006-6196
Disclosure Date: December 01, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the search functionality in Fixit iDMS Pro Image Gallery allows remote attackers to inject arbitrary web script or HTML via a search field (txtsearchtext parameter).
0
Attacker Value
Unknown
CVE-2006-6195
Disclosure Date: December 01, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Fixit iDMS Pro Image Gallery allow remote attackers to execute arbitrary SQL commands via the (1) show_id or (2) parentid parameter to (a) filelist.asp, or the (3) fid parameter to (b) showfile.asp.
0