Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2017-15967

Disclosure Date: October 29, 2017 (last updated November 26, 2024)
Mailing List Manager Pro 3.0 allows SQL Injection via the edit parameter to admin/users in a sort=login action, or the edit parameter to admin/template.
0
Attacker Value
Unknown

CVE-2011-3816

Disclosure Date: September 24, 2011 (last updated October 04, 2023)
WEBinsta mailing list manager 1.3e allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by install/install3.php and certain other files.
0
Attacker Value
Unknown

CVE-2008-5979

Disclosure Date: January 27, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in default.asp in Ocean12 Mailing List Manager Gold allows remote attackers to inject arbitrary web script or HTML via the Email parameter.
0
Attacker Value
Unknown

CVE-2008-5978

Disclosure Date: January 27, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Ocean12 Mailing List Manager Gold allow remote attackers to execute arbitrary SQL commands via the Email parameter to (1) default.asp and (2) s_edit.asp.
0
Attacker Value
Unknown

CVE-2008-5980

Disclosure Date: January 27, 2009 (last updated October 04, 2023)
Ocean12 Mailing List Manager Gold stores sensitive data under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for o12mail.mdb.
0
Attacker Value
Unknown

CVE-2008-5606

Disclosure Date: December 16, 2008 (last updated October 04, 2023)
Gazatem QMail Mailing List Manager 1.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for qmail.mdb.
0
Attacker Value
Unknown

CVE-2006-4209

Disclosure Date: August 17, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in install3.php in WEBInsta Mailing List Manager 1.3e allows remote attackers to execute arbitrary PHP code via a URL in the cabsolute_path parameter.
0
Attacker Value
Unknown

CVE-2005-1419

Disclosure Date: May 03, 2005 (last updated February 22, 2025)
SQL injection vulnerability in the admin login panel for Ocean12 Mailing List Manager 1.06 allows remote attackers to execute arbitrary SQL commands via the Admin_id parameter.
0
Attacker Value
Unknown

CVE-2004-2744

Disclosure Date: December 31, 2004 (last updated October 04, 2023)
Unspecified vulnerability in Tincan Limited PHPlist before 2.8.12 has unknown impact and attack vectors, related to a "security update release."
0
Attacker Value
Unknown

CVE-2003-1313

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Multiple PHP remote file inclusion vulnerabilities in EternalMart Mailing List Manager (EMLM) 1.32 allow remote attackers to execute arbitrary PHP code via a URL in (1) the emml_admin_path parameter to admin/auth.php or (2) the emml_path parameter to emml_email_func.php.
0