Show filters
95 Total Results
Displaying 81-90 of 95
Sort by:
Attacker Value
Unknown

CVE-2006-6150

Disclosure Date: November 28, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in memory/OWLMemoryProperty.php in OWLLib 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the OWLLIB_ROOT parameter.
0
Attacker Value
Unknown

CVE-2006-5518

Disclosure Date: October 26, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Christopher Fowler (Rhode Island) RSSonate allow remote attackers to execute arbitrary PHP code via a URL in the PROJECT_ROOT parameter to (1) xml2rss.php, (2) config_local.php, (3) rssonate.php, and (4) sql2xml.php in Src/getFeed/inc/.
0
Attacker Value
Unknown

CVE-2006-2885

Disclosure Date: June 07, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in KnowledgeTree Open Source 3.0.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) fDocumentId parameter in view.php and the (2) fSearchableText parameter in /search/simpleSearch.php.
0
Attacker Value
Unknown

CVE-2006-2443

Disclosure Date: May 18, 2006 (last updated October 04, 2023)
The Debian package of knowledgetree 2.0.7 creates environment.php with world-readable permissions, which allows local users to obtain sensitive information such as the username and password for the KnowledgeTree database.
0
Attacker Value
Unknown

CVE-2006-1294

Disclosure Date: March 19, 2006 (last updated February 22, 2025)
PHP remote file include vulnerability in PageController.php in KnowledgebasePublisher 1.2 allows remote attackers to include and execute arbitrary PHP code via a URL in the dir parameter.
0
Attacker Value
Unknown

CVE-2006-1149

Disclosure Date: March 10, 2006 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in lib/OWL_API.php in OWL Intranet Engine 0.82, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the xrms_file_root parameter, which is not initialized before use.
0
Attacker Value
Unknown

CVE-2005-3939

Disclosure Date: December 01, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in WSN Knowledge Base 1.2.0 and earler allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) perpage, (3) ascdesc, and (4) orderlinks in a displaycat action in (a) index.php; and the (5) id parameter in (b) comments.php and (c) memberlist.php.
0
Attacker Value
Unknown

CVE-2005-0264

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in browse.php in OWL 0.7 and 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) expand or (2) order parameter.
0
Attacker Value
Unknown

CVE-2005-0265

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in browse.php in OWL 0.7 and 0.8 allow remote attackers to execute arbitrary SQL commands via the (1) parent or (2) sortposted parameter.
0
Attacker Value
Unknown

CVE-2003-1449

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Aladdin Knowlege Systems eSafe Gateway 3.5.126.0 does not check the entire stream of Content Vectoring Protocol (CVP) data, which allows remote attackers to bypass virus protection.
0