Show filters
89 Total Results
Displaying 81-89 of 89
Sort by:
Attacker Value
Unknown
CVE-2008-1059
Disclosure Date: February 28, 2008 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the libpath parameter.
0
Attacker Value
Unknown
CVE-2008-1061
Disclosure Date: February 28, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to (a) warning.php, (b) notice.php, and (c) inset.php in view/sniplets/, and possibly (d) modules/execute.php; the (2) url parameter to (e) view/admin/submenu.php; and the (3) page parameter to (f) view/admin/pager.php.
0
Attacker Value
Unknown
CVE-2008-1060
Disclosure Date: February 28, 2008 (last updated October 04, 2023)
Eval injection vulnerability in modules/execute.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute arbitrary PHP code via the text parameter.
0
Attacker Value
Unknown
CVE-2007-1962
Disclosure Date: April 11, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the WF-Snippets 1.02 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL commands via the c parameter in a cat action.
0
Attacker Value
Unknown
CVE-2006-1826
Disclosure Date: April 18, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Snipe Gallery 3.1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gallery_id parameter in view.php, (2) keyword parameter in search.php, and (3) image_id parameter in image.php. NOTE: it is possible that vectors 1 and 3 are resultant from SQL injection.
0
Attacker Value
Unknown
CVE-2005-4244
Disclosure Date: December 14, 2005 (last updated February 22, 2025)
SQL injection vulnerability in Snipe Gallery 3.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) gallery_id parameter to view.php and (2) image_id parameter to image.php.
0
Attacker Value
Unknown
CVE-2005-4245
Disclosure Date: December 14, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in search.php in Snipe Gallery 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.
0
Attacker Value
Unknown
CVE-2004-1746
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in index.php in PHP Code Snippet Library allows remote attackers to inject arbitrary web script or HTML via the (1) cat_select or (2) show parameters.
0
Attacker Value
Unknown
CVE-2004-1470
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
CRLF injection vulnerability in SnipSnap 0.5.2a, and other versions before 1.0b1, allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server.
0