Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2022-27412

Disclosure Date: May 09, 2022 (last updated February 23, 2025)
Explore CMS v1.0 was discovered to contain a SQL injection vulnerability via a /page.php?id= request.
Attacker Value
Unknown

CVE-2012-0396

Disclosure Date: February 06, 2012 (last updated October 04, 2023)
EMC Documentum xPlore 1.0, 1.1 before P07, and 1.2 does not properly enforce the requirement for BROWSE permission, which allows remote authenticated users to determine the existence of an object, or read object metadata, via a search.
0
Attacker Value
Unknown

CVE-2008-3353

Disclosure Date: July 28, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Pure Software Lore before 1.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the (1) article comments feature and the (2) search log feature.
0
Attacker Value
Unknown

CVE-2007-2021

Disclosure Date: April 12, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Pineapple Technologies Lore 1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lang_path parameter to third_party/phpmailer/class.phpmailer.php or the (2) get_plugin_file_path parameter to third_party/smarty/libs/plugins/function.html_checkboxes.php. NOTE: the affected files might be from other software packages, so this might not be a vulnerability in Lore itself. NOTE: (1) might be the same issue as CVE-2006-5734.4.
0