Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2007-5724
Disclosure Date: October 30, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Omnistar Live allow remote attackers to inject arbitrary web script or HTML via (1) the category_id parameter to users/kb.php, and possibly (3) the Email Box field in profile.php.
0
Attacker Value
Unknown
CVE-2007-4952
Disclosure Date: September 18, 2007 (last updated October 04, 2023)
SQL injection vulnerability in article.php in OmniStar Article Manager allows remote attackers to execute arbitrary SQL commands via the page_id parameter in a favorite op action, a different vector than CVE-2006-5917.
0
Attacker Value
Unknown
CVE-2006-5917
Disclosure Date: November 15, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in OmniStar Article Manager allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter in (a) articles/comments.php and (b) articles/article.php, and the (2) page_id parameter in (c) articles/pages.php.
0
Attacker Value
Unknown
CVE-2005-3880
Disclosure Date: November 29, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in Omnistar KBase 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter in users/comments.php, (2) category_id and (3) id parameters in users/kb.php.
0
Attacker Value
Unknown
CVE-2005-3840
Disclosure Date: November 26, 2005 (last updated February 22, 2025)
SQL injection vulnerability in kb.php in Omnistar Live 5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category_id parameter. NOTE: due to a typo, an Internet Explorer issue was incorrectly assigned this identifier, but the correct identifier is CVE-2005-3240.
0