Show filters
29 Total Results
Displaying 1-10 of 29
Sort by:
Attacker Value
Unknown

CVE-2010-4097

Disclosure Date: October 27, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Aardvark Topsites PHP 5.2.0 and 5.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) mail, (2) title, (3) u, and (4) url parameters. NOTE: the q parameter is already covered by CVE-2009-2302.
0
Attacker Value
Unknown

CVE-2008-7071

Disclosure Date: August 25, 2009 (last updated October 04, 2023)
SQL injection vulnerability in authenticate.php in Chipmunk Topsites allows remote attackers to execute arbitrary SQL commands via the username parameter, related to login.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-7072

Disclosure Date: August 25, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in Chipmunk Topsites allows remote attackers to inject arbitrary web script or HTML via the start parameter.
0
Attacker Value
Unknown

CVE-2009-2302

Disclosure Date: July 02, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in Aardvark Topsites PHP 5.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action. NOTE: it was later reported that 5.2.1 is also affected.
0
Attacker Value
Unknown

CVE-2009-2304

Disclosure Date: July 02, 2009 (last updated October 04, 2023)
index.php in Aardvark Topsites PHP 5.2.0 and earlier allows remote attackers to obtain sensitive information via a nonexistent account name in the u parameter in a rate action, which reveals the installation path in an error message.
0
Attacker Value
Unknown

CVE-2009-2303

Disclosure Date: July 02, 2009 (last updated October 04, 2023)
index.php in Aardvark Topsites PHP 5.2.1 and earlier allows remote attackers to obtain sensitive information via a negative integer value for the start parameter in a search action, which reveals the installation path in an error message.
0
Attacker Value
Unknown

CVE-2008-1784

Disclosure Date: April 15, 2008 (last updated October 04, 2023)
Prozilla Topsites 1.0 allows remote attackers to perform administrative actions via a direct request to (1) addu.php, (2) editu.php, and (3) uidx.php in siteadmin/.
0
Attacker Value
Unknown

CVE-2007-5918

Disclosure Date: November 10, 2007 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in edit.php in the MS TopSites add-on for PHP-Nuke does not verify that the uname parameter matches the current account, which allows remote authenticated users to change arbitrary accounts or change the SiteTitleName field as an arbitrary user via a modified uname value in an edit action to modules.php.
0
Attacker Value
Unknown

CVE-2007-2155

Disclosure Date: April 19, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in template.php in in phpFaber TopSites 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the modify parameter in a template action to admin/index.php.
0
Attacker Value
Unknown

CVE-2007-1844

Disclosure Date: April 03, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Aardvark Topsites PHP 5 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) button/settings_sql.php, (2) settings_sql.php, and (3) sources/misc/new_day.php.
0