Search CVE reports


Toggle filters

641 – 650 of 672 results


CVE-2008-4810

Medium priority

Some fixes available 2 of 9

The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 before r2797 allows remote attackers to execute arbitrary PHP code via vectors related to templates and (1) a dollar-sign character, aka "php...

3 affected packages

gallery2, moodle, smarty

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gallery2 — — — — —
moodle — — — — —
smarty — — — — —
Show less packages

CVE-2008-4796

Medium priority

Some fixes available 2 of 23

The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other products, allows remote...

10 affected packages

ampache, gforge-plugin-scmcvs, libphp-snoopy, magpierss, mahara...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ampache — — — — —
gforge-plugin-scmcvs — — — — —
libphp-snoopy — — — — —
magpierss — — — — —
mahara — — — — —
mediamate — — — — —
moodle — — — — —
opendb — — — — —
pixelpost — — — — —
wordpress — — — — —
Show all 10 packages Show less packages

CVE-2008-3327

Negligible priority
Ignored

Moodle 1.6.5, when display_errors is enabled, allows remote attackers to obtain sensitive information via a direct request to (1) blog/blogpage.php and (2) course/report/stats/report.php, which reveals the installation path in an...

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle — — — — —
Show less packages

CVE-2008-3326

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in blog/edit.php in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to inject arbitrary web script or HTML via the etitle parameter (blog entry title).

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle — — — — —
Show less packages

CVE-2008-3325

Medium priority
Ignored

Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile settings and gain privileges as other users via a link or IMG tag to the user edit profile page.

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle — — — — —
Show less packages

CVE-2008-1502

Medium priority

Some fixes available 6 of 13

The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and other products, allows remote attackers to bypass HTML filtering and conduct cross-site...

2 affected packages

egroupware, moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
egroupware — — — — —
moodle — — — — —
Show less packages

CVE-2008-0123

Negligible priority
Ignored

Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML via the dbname parameter. NOTE: this issue only...

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle — — — — —
Show less packages

CVE-2007-6538

Medium priority
Not affected

SQL injection vulnerability in ing/blocks/mrbs/code/web/view_entry.php in the MRBS plugin for Moodle allows remote attackers to execute arbitrary SQL commands via the id parameter.

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle — — — — —
Show less packages

CVE-2007-3555

Low priority
Ignored

Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expression in the search parameter, a different vulnerability than CVE-2004-1424.

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle — — — — —
Show less packages

CVE-2007-3215

Medium priority

Some fixes available 25 of 38

PHPMailer 1.7, when configured to use sendmail, allows remote attackers to execute arbitrary shell commands via shell metacharacters in the SendmailSend function in class.phpmailer.php.

8 affected packages

flyspray, glpi, ipplan, knowledgeroot, libphp-phpmailer...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
flyspray — — — — —
glpi — — — — —
ipplan — — — — —
knowledgeroot — — — — —
libphp-phpmailer — — — — —
moodle — — — — —
owl-dms — — — — —
wordpress — — — — —
Show all 8 packages Show less packages