Show filters
95 Total Results
Displaying 81-90 of 95
Sort by:
Attacker Value
Unknown
CVE-2006-6150
Disclosure Date: November 28, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in memory/OWLMemoryProperty.php in OWLLib 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the OWLLIB_ROOT parameter.
0
Attacker Value
Unknown
CVE-2006-5518
Disclosure Date: October 26, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Christopher Fowler (Rhode Island) RSSonate allow remote attackers to execute arbitrary PHP code via a URL in the PROJECT_ROOT parameter to (1) xml2rss.php, (2) config_local.php, (3) rssonate.php, and (4) sql2xml.php in Src/getFeed/inc/.
0
Attacker Value
Unknown
CVE-2006-2885
Disclosure Date: June 07, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in KnowledgeTree Open Source 3.0.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) fDocumentId parameter in view.php and the (2) fSearchableText parameter in /search/simpleSearch.php.
0
Attacker Value
Unknown
CVE-2006-2443
Disclosure Date: May 18, 2006 (last updated October 04, 2023)
The Debian package of knowledgetree 2.0.7 creates environment.php with world-readable permissions, which allows local users to obtain sensitive information such as the username and password for the KnowledgeTree database.
0
Attacker Value
Unknown
CVE-2006-1294
Disclosure Date: March 19, 2006 (last updated February 22, 2025)
PHP remote file include vulnerability in PageController.php in KnowledgebasePublisher 1.2 allows remote attackers to include and execute arbitrary PHP code via a URL in the dir parameter.
0
Attacker Value
Unknown
CVE-2006-1149
Disclosure Date: March 10, 2006 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in lib/OWL_API.php in OWL Intranet Engine 0.82, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the xrms_file_root parameter, which is not initialized before use.
0
Attacker Value
Unknown
CVE-2005-3939
Disclosure Date: December 01, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in WSN Knowledge Base 1.2.0 and earler allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) perpage, (3) ascdesc, and (4) orderlinks in a displaycat action in (a) index.php; and the (5) id parameter in (b) comments.php and (c) memberlist.php.
0
Attacker Value
Unknown
CVE-2005-0264
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in browse.php in OWL 0.7 and 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) expand or (2) order parameter.
0
Attacker Value
Unknown
CVE-2005-0265
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in browse.php in OWL 0.7 and 0.8 allow remote attackers to execute arbitrary SQL commands via the (1) parent or (2) sortposted parameter.
0
Attacker Value
Unknown
CVE-2003-1449
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Aladdin Knowlege Systems eSafe Gateway 3.5.126.0 does not check the entire stream of Content Vectoring Protocol (CVP) data, which allows remote attackers to bypass virus protection.
0