Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown
CVE-2017-15967
Disclosure Date: October 29, 2017 (last updated November 26, 2024)
Mailing List Manager Pro 3.0 allows SQL Injection via the edit parameter to admin/users in a sort=login action, or the edit parameter to admin/template.
0
Attacker Value
Unknown
CVE-2011-3816
Disclosure Date: September 24, 2011 (last updated October 04, 2023)
WEBinsta mailing list manager 1.3e allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by install/install3.php and certain other files.
0
Attacker Value
Unknown
CVE-2008-5979
Disclosure Date: January 27, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in default.asp in Ocean12 Mailing List Manager Gold allows remote attackers to inject arbitrary web script or HTML via the Email parameter.
0
Attacker Value
Unknown
CVE-2008-5978
Disclosure Date: January 27, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Ocean12 Mailing List Manager Gold allow remote attackers to execute arbitrary SQL commands via the Email parameter to (1) default.asp and (2) s_edit.asp.
0
Attacker Value
Unknown
CVE-2008-5980
Disclosure Date: January 27, 2009 (last updated October 04, 2023)
Ocean12 Mailing List Manager Gold stores sensitive data under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for o12mail.mdb.
0
Attacker Value
Unknown
CVE-2008-5606
Disclosure Date: December 16, 2008 (last updated October 04, 2023)
Gazatem QMail Mailing List Manager 1.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for qmail.mdb.
0
Attacker Value
Unknown
CVE-2006-4209
Disclosure Date: August 17, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in install3.php in WEBInsta Mailing List Manager 1.3e allows remote attackers to execute arbitrary PHP code via a URL in the cabsolute_path parameter.
0
Attacker Value
Unknown
CVE-2005-1419
Disclosure Date: May 03, 2005 (last updated February 22, 2025)
SQL injection vulnerability in the admin login panel for Ocean12 Mailing List Manager 1.06 allows remote attackers to execute arbitrary SQL commands via the Admin_id parameter.
0
Attacker Value
Unknown
CVE-2004-2744
Disclosure Date: December 31, 2004 (last updated October 04, 2023)
Unspecified vulnerability in Tincan Limited PHPlist before 2.8.12 has unknown impact and attack vectors, related to a "security update release."
0
Attacker Value
Unknown
CVE-2003-1313
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Multiple PHP remote file inclusion vulnerabilities in EternalMart Mailing List Manager (EMLM) 1.32 allow remote attackers to execute arbitrary PHP code via a URL in (1) the emml_admin_path parameter to admin/auth.php or (2) the emml_path parameter to emml_email_func.php.
0