Show filters
194 Total Results
Displaying 81-90 of 194
Sort by:
Attacker Value
Unknown

CVE-2010-4778

Disclosure Date: April 04, 2011 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in fetchmailprefs.php in Horde IMP before 4.3.8, and Horde Groupware Webmail Edition before 1.2.7, allow remote attackers to inject arbitrary web script or HTML via the (1) username (aka fmusername), (2) password (aka fmpassword), or (3) server (aka fmserver) field in a fetchmail_prefs_save action, related to the Fetchmail configuration, a different issue than CVE-2010-3695. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2010-3693

Disclosure Date: April 04, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Horde Dynamic IMP (DIMP) before 1.1.5, and Horde Groupware Webmail Edition before 1.2.7, allows remote attackers to inject arbitrary web script or HTML via vectors related to displaying mailbox names.
0
Attacker Value
Unknown

CVE-2010-3695

Disclosure Date: March 31, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in fetchmailprefs.php in Horde IMP before 4.3.8, and Horde Groupware Webmail Edition before 1.2.7, allows remote attackers to inject arbitrary web script or HTML via the fm_id parameter in a fetchmail_prefs_save action, related to the Fetchmail configuration.
0
Attacker Value
Unknown

CVE-2010-3313

Disclosure Date: September 22, 2010 (last updated October 04, 2023)
phpgwapi/js/fckeditor/editor/dialog/fck_spellerpages/spellerpages/serverscripts/spellchecker.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003; and EPL 9.1 before 9.1.20100309 and 9.2 before 9.2.20100309; allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) aspell_path or (2) spellchecker_lang parameters.
0
Attacker Value
Unknown

CVE-2010-3314

Disclosure Date: September 22, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in login.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003; and EPL 9.1 before 9.1.20100309 and 9.2 before 9.2.20100309; allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
0
Attacker Value
Unknown

CVE-2010-0404

Disclosure Date: May 19, 2010 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in phpGroupWare (phpgw) before 0.9.16.016 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) class.sessions_db.inc.php, (2) class.translation_sql.inc.php, or (3) class.auth_sql.inc.php in phpgwapi/inc/.
0
Attacker Value
Unknown

CVE-2010-0403

Disclosure Date: May 19, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in about.php in phpGroupWare (phpgw) before 0.9.16.016 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the app parameter.
0
Attacker Value
Unknown

CVE-2010-1135

Disclosure Date: March 27, 2010 (last updated October 04, 2023)
The user_logout function in TikiWiki CMS/Groupware 4.x before 4.2 does not properly delete user login cookies, which allows remote attackers to gain access via cookie reuse.
0
Attacker Value
Unknown

CVE-2010-1134

Disclosure Date: March 27, 2010 (last updated October 04, 2023)
SQL injection vulnerability in the _find function in searchlib.php in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to execute arbitrary SQL commands via the $searchDate variable.
0
Attacker Value
Unknown

CVE-2010-1133

Disclosure Date: March 27, 2010 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in TikiWiki CMS/Groupware 4.x before 4.2 allow remote attackers to execute arbitrary SQL commands via unspecified vectors, probably related to (1) tiki-searchindex.php and (2) tiki-searchresults.php.
0