Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2009-4429

Disclosure Date: December 28, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Sections module 5.x before 5.x-1.3 and 6.x before 6.x-1.3 for Drupal allows remote authenticated users with "administer sections" privileges to inject arbitrary web script or HTML via a section name (aka the Name field).
0
Attacker Value
Unknown

CVE-2008-6865

Disclosure Date: July 14, 2009 (last updated October 04, 2023)
SQL injection vulnerability in modules.php in the Sectionsnew module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the artid parameter in a printpage action.
0
Attacker Value
Unknown

CVE-2007-1974

Disclosure Date: April 12, 2007 (last updated October 04, 2023)
SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as used in Xoops modules such as (1) Zmagazine 1.0, (2) Happy Linux XFsection 1.07 and earlier, and possibly other modules, allows remote attackers to execute arbitrary SQL commands via the articleid parameter to print.php.
0
Attacker Value
Unknown

CVE-2006-3598

Disclosure Date: July 18, 2006 (last updated October 04, 2023)
SQL injection vulnerability in the Sections module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the artid parameter in a viewarticle op.
0