Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown
CVE-2010-4155
Disclosure Date: November 03, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) rssfeedURL parameter to manual/caferss/example.php and the sumb parameter to (2) modules/news/archive.php, (3) modules/news/topics.php, and (4) modules/contact/index.php, different vectors than CVE-2007-1965.
0
Attacker Value
Unknown
CVE-2008-1406
Disclosure Date: March 20, 2008 (last updated October 04, 2023)
SQL injection vulnerability in annonces-p-f.php in the MyAnnonces 1.8 module for eXV2 allows remote attackers to execute arbitrary SQL commands via the lid parameter in an ImprAnn action.
0
Attacker Value
Unknown
CVE-2008-1404
Disclosure Date: March 20, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the Viso (Industry Book) 2.04 and 2.03 module for eXV2 allows remote attackers to execute arbitrary SQL commands via the kid parameter.
0
Attacker Value
Unknown
CVE-2008-1407
Disclosure Date: March 20, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the WebChat 1.60 module for eXV2 allows remote attackers to execute arbitrary SQL commands via the roomid parameter.
0
Attacker Value
Unknown
CVE-2008-1349
Disclosure Date: March 17, 2008 (last updated October 04, 2023)
SQL injection vulnerability in viewcat.php in the bamaGalerie (Bama Galerie) 3.03 and 3.041 module for eXV2 2.0.6 allows remote attackers to execute arbitrary SQL commands via the cid parameter.
0
Attacker Value
Unknown
CVE-2007-4365
Disclosure Date: August 15, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in eXV2 CMS 2.0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a set_lang cookie to an unspecified component. NOTE: this may overlap CVE-2007-1965.
0
Attacker Value
Unknown
CVE-2007-1965
Disclosure Date: April 11, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.0.4.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the set_lang parameter to (1) archive.php, (2) article.php, (3) index.php, or (4) topics.php.
0
Attacker Value
Unknown
CVE-2007-1966
Disclosure Date: April 11, 2007 (last updated October 04, 2023)
Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cookie.
0
Attacker Value
Unknown
CVE-2006-7079
Disclosure Date: March 02, 2007 (last updated January 27, 2024)
Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables and conduct directory traversal attacks to execute arbitrary code by modifying the $xoopsOption['pagetype'] variable.
0
Attacker Value
Unknown
CVE-2006-7080
Disclosure Date: March 02, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to delete arbitrary files via ".." sequences in the old_avatar parameter.
0