Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown

CVE-2010-4155

Disclosure Date: November 03, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) rssfeedURL parameter to manual/caferss/example.php and the sumb parameter to (2) modules/news/archive.php, (3) modules/news/topics.php, and (4) modules/contact/index.php, different vectors than CVE-2007-1965.
0
Attacker Value
Unknown

CVE-2008-1406

Disclosure Date: March 20, 2008 (last updated October 04, 2023)
SQL injection vulnerability in annonces-p-f.php in the MyAnnonces 1.8 module for eXV2 allows remote attackers to execute arbitrary SQL commands via the lid parameter in an ImprAnn action.
0
Attacker Value
Unknown

CVE-2008-1404

Disclosure Date: March 20, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the Viso (Industry Book) 2.04 and 2.03 module for eXV2 allows remote attackers to execute arbitrary SQL commands via the kid parameter.
0
Attacker Value
Unknown

CVE-2008-1407

Disclosure Date: March 20, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the WebChat 1.60 module for eXV2 allows remote attackers to execute arbitrary SQL commands via the roomid parameter.
0
Attacker Value
Unknown

CVE-2008-1349

Disclosure Date: March 17, 2008 (last updated October 04, 2023)
SQL injection vulnerability in viewcat.php in the bamaGalerie (Bama Galerie) 3.03 and 3.041 module for eXV2 2.0.6 allows remote attackers to execute arbitrary SQL commands via the cid parameter.
0
Attacker Value
Unknown

CVE-2007-4365

Disclosure Date: August 15, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in eXV2 CMS 2.0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a set_lang cookie to an unspecified component. NOTE: this may overlap CVE-2007-1965.
0
Attacker Value
Unknown

CVE-2007-1965

Disclosure Date: April 11, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.0.4.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the set_lang parameter to (1) archive.php, (2) article.php, (3) index.php, or (4) topics.php.
0
Attacker Value
Unknown

CVE-2007-1966

Disclosure Date: April 11, 2007 (last updated October 04, 2023)
Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cookie.
0
Attacker Value
Unknown

CVE-2006-7079

Disclosure Date: March 02, 2007 (last updated January 27, 2024)
Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables and conduct directory traversal attacks to execute arbitrary code by modifying the $xoopsOption['pagetype'] variable.
Attacker Value
Unknown

CVE-2006-7080

Disclosure Date: March 02, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to delete arbitrary files via ".." sequences in the old_avatar parameter.
0