Show filters
107 Total Results
Displaying 91-100 of 107
Sort by:
Attacker Value
Unknown
CVE-2014-10015
Disclosure Date: January 13, 2015 (last updated October 05, 2023)
SQL injection vulnerability in load-calendar.php in PHPJabbers Event Booking Calendar 2.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter.
0
Attacker Value
Unknown
CVE-2014-10010
Disclosure Date: January 13, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in PHPJabbers Appointment Scheduler 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a pjActionDownload action to the pjBackup controller.
0
Attacker Value
Unknown
CVE-2014-10014
Disclosure Date: January 13, 2015 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Event Booking Calendar 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) change the username and password of the administrator via an update action to the AdminOptions controller or conduct cross-site scripting (XSS) attacks via the (2) event_title parameter in a create action to the AdminEvents controller or (3) category_title parameter in a create action to the AdminCategories controller.
0
Attacker Value
Unknown
CVE-2012-3525
Disclosure Date: August 25, 2012 (last updated October 04, 2023)
s2s/out.c in jabberd2 2.2.16 and earlier does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via a (1) Verify Response or (2) Authorization Response.
0
Attacker Value
Unknown
CVE-2012-4324
Disclosure Date: August 14, 2012 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in PHPJabbers Vacation Rental Script allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts via a create action in the AdminUsers module to index.php.
0
Attacker Value
Unknown
CVE-2011-1754
Disclosure Date: June 21, 2011 (last updated October 04, 2023)
jabberd14 1.6.1.1 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
0
Attacker Value
Unknown
CVE-2011-1755
Disclosure Date: June 21, 2011 (last updated February 03, 2024)
jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
0
Attacker Value
Unknown
CVE-2008-6937
Disclosure Date: August 11, 2009 (last updated October 04, 2023)
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cause a denial of service via encoded spaces in an xmpp:// URI, a different vector than CVE-2008-6935 and CVE-2008-6936. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2008-6936
Disclosure Date: August 11, 2009 (last updated October 04, 2023)
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cause a denial of service via encoded spaces in a pres:// URI, a different vector than CVE-2008-6935.
0
Attacker Value
Unknown
CVE-2008-4721
Disclosure Date: October 23, 2008 (last updated October 04, 2023)
PHP Jabbers Post Comment 3.0 allows remote attackers to bypass authentication and gain administrative access by setting the PostCommentsAdmin cookie to "logged."
0