Show filters
105 Total Results
Displaying 81-90 of 105
Sort by:
Attacker Value
Unknown

CVE-2007-2889

Disclosure Date: May 30, 2007 (last updated October 04, 2023)
SQL injection vulnerability in tracking/courseLog.php in Dokeos 1.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the scormcontopen parameter.
0
Attacker Value
Unknown

CVE-2007-2849

Disclosure Date: May 24, 2007 (last updated October 04, 2023)
KnowledgeTree Document Management (aka KnowledgeTree Open Source) before STABLE 3.3.7 does not require a password for an unregistered user, when the user exists in Active Directory, which allows remote attackers to log onto KTDMS without the intended authorization check.
0
Attacker Value
Unknown

CVE-2007-1039

Disclosure Date: February 21, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Peanut Knowledge Base (PeanutKB) 0.0.3 and earlier has unknown impact and attack vectors.
0
Attacker Value
Unknown

CVE-2006-5919

Disclosure Date: November 15, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in admin/e_data/visEdit_control.class.php in ActiveCampaign KnowledgeBuilder 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the visEdit_root parameter, a different vector than CVE-2003-1131.
0
Attacker Value
Unknown

CVE-2006-5496

Disclosure Date: October 25, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Timothy Claason KnowledgeBank 1.01 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) index.php, (2) addknowledge.php, and (3) addscreenshot.php.
0
Attacker Value
Unknown

CVE-2006-4844

Disclosure Date: September 19, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeos and possibly other products, allows remote attackers to execute arbitrary PHP code via a URL in the extAuthSource[newUser] parameter.
0
Attacker Value
Unknown

CVE-2006-2885

Disclosure Date: June 07, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in KnowledgeTree Open Source 3.0.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) fDocumentId parameter in view.php and the (2) fSearchableText parameter in /search/simpleSearch.php.
0
Attacker Value
Unknown

CVE-2006-2886

Disclosure Date: June 07, 2006 (last updated October 04, 2023)
view.php in KnowledgeTree Open Source 3.0.3 and earlier allows remote attackers to obtain the full installation path via a crafted fDocumentId parameter, which displays the path in the resulting error message. NOTE: this might be resultant from another vulnerability, since this vector also produces XSS.
0
Attacker Value
Unknown

CVE-2006-2443

Disclosure Date: May 18, 2006 (last updated October 04, 2023)
The Debian package of knowledgetree 2.0.7 creates environment.php with world-readable permissions, which allows local users to obtain sensitive information such as the username and password for the KnowledgeTree database.
0
Attacker Value
Unknown

CVE-2006-2285

Disclosure Date: May 10, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in authldap.php in Dokeos 1.6.4 allows remote attackers to execute arbitrary PHP code via a URL in the includePath parameter.
0