Show filters
105 Total Results
Displaying 91-100 of 105
Sort by:
Attacker Value
Unknown

CVE-2006-2184

Disclosure Date: May 04, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in search.php in PHPKB Knowledge Base allows remote attackers to inject arbitrary web script or HTML via the searchkeyword parameter. NOTE: the issue was originally disputed by the vendor, but on 20060519, the vendor notified CVE that "We have fixed all the mentioned issues and now the search section of PHPKB script is free from any XSS issues."
0
Attacker Value
Unknown

CVE-2006-1438

Disclosure Date: April 03, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Andy's PHP Knowledgebase (aphpkb) 0.57 allow remote attackers to inject arbitrary web script or HTML via the (1) keyword_list parameter to (a) index.php; (2) title, (3) article, (4) author, and (5) keywords parameters to (b) submit_article.php; and (6) Question, (7) Name, and (8) Email parameters to (c) submit_question.php.
0
Attacker Value
Unknown

CVE-2006-1294

Disclosure Date: March 19, 2006 (last updated February 22, 2025)
PHP remote file include vulnerability in PageController.php in KnowledgebasePublisher 1.2 allows remote attackers to include and execute arbitrary PHP code via a URL in the dir parameter.
0
Attacker Value
Unknown

CVE-2006-0970

Disclosure Date: March 03, 2006 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in index.php in one or more ActiveCampaign products, possibly SupportTrio, allows remote attackers to include and execute arbitrary files via the page parameter.
0
Attacker Value
Unknown

CVE-2005-4658

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in ASP-Programmers.com ASPKnowledgebase allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in the administrative interface.
0
Attacker Value
Unknown

CVE-2005-3653

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field.
0
Attacker Value
Unknown

CVE-2005-4047

Disclosure Date: December 07, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in kb.asp in IISWorks ASPKnowledgeBase 2.0 allows remote attackers to inject arbitrary web script or HTML via the a parameter.
0
Attacker Value
Unknown

CVE-2005-3942

Disclosure Date: December 01, 2005 (last updated February 22, 2025)
SQL injection vulnerability in knowledgebase-control.php in Orca Knowledgebase 2.1b and earlier allows remote attackers to execute arbitrary SQL commands via the qid parameter.
0
Attacker Value
Unknown

CVE-2005-3939

Disclosure Date: December 01, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in WSN Knowledge Base 1.2.0 and earler allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) perpage, (3) ascdesc, and (4) orderlinks in a displaycat action in (a) index.php; and the (5) id parameter in (b) comments.php and (c) memberlist.php.
0
Attacker Value
Unknown

CVE-2005-3881

Disclosure Date: November 29, 2005 (last updated February 22, 2025)
SQL injection vulnerability in search.php in AtlantisFAQ Knowledge Base Software 2.03 and earlier allows remote attackers to execute arbitrary SQL commands via the searchStr parameter.
0