Show filters
121 Total Results
Displaying 81-90 of 121
Sort by:
Attacker Value
Unknown

CVE-2003-1587

Disclosure Date: February 05, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in LoganPro allows remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header.
0
Attacker Value
Unknown

CVE-2008-4898

Disclosure Date: November 04, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in planetluc RateMe 1.3.3 allows remote attackers to inject arbitrary web script or HTML via the rate parameter in a submit rate action.
0
Attacker Value
Unknown

CVE-2008-4891

Disclosure Date: November 04, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in signme.inc.php in Planetluc SignMe 1.5 before 1.55 allows remote attackers to inject arbitrary web script or HTML via the hash parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-4899

Disclosure Date: November 04, 2008 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in Planetluc RateMe 1.3.3 allows remote attackers to perform unauthorized actions as other users via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-4892

Disclosure Date: November 04, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in gallery.inc.php in Planetluc MyGallery 1.7.2 and earlier, and possibly other versions before 1.8.1, allows remote attackers to inject arbitrary web script or HTML via the mghash parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-3304

Disclosure Date: July 25, 2008 (last updated October 04, 2023)
BilboBlog 0.2.1 allows remote attackers to obtain sensitive information via (1) an enable_cache=false query string to footer.php or (2) a direct request to pagination.php, which reveals the installation path in an error message.
0
Attacker Value
Unknown

CVE-2008-3302

Disclosure Date: July 25, 2008 (last updated October 04, 2023)
SQL injection vulnerability in admin/delete.php in BilboBlog 0.2.1, when magic_quotes_gpc is disabled, allows remote authenticated administrators to execute arbitrary SQL commands via the num parameter.
0
Attacker Value
Unknown

CVE-2008-3303

Disclosure Date: July 25, 2008 (last updated October 04, 2023)
admin/login.php in BilboBlog 0.2.1, when register_globals is enabled, allows remote attackers to bypass authentication and obtain administrative access via a direct request that sets the login, admin_login, password, and admin_passwd parameters.
0
Attacker Value
Unknown

CVE-2008-3301

Disclosure Date: July 25, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in BilboBlog 0.2.1 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) content parameter to admin/update.php, related to conflicting code in widget.php; and allow remote attackers to inject arbitrary web script or HTML via the (2) titleId parameter to head.php, reachable through index.php; the (3) t_lang[lang_copyright] parameter to footer.php; the (4) content parameter to the default URI under admin/; the (5) url, (6) t_lang[lang_admin_help], (7) t_lang[lang_admin_clear_cache], (8) t_lang[lang_admin_home], and (9) t_lang[lang_admin_logout] parameters to admin/homelink.php; and the (10) t_lang[lang_admin_new_post] parameter to admin/post.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-0723

Disclosure Date: February 12, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in mynews.inc.php in MyNews 1.6.4, and other earlier 1.6.x versions, allows remote attackers to inject arbitrary web script or HTML via the hash parameter in an admin action to index.php, a different vulnerability than CVE-2006-2208.1.
0