Skip to content
Noroxi

Xoops records

101 published records for vendor xoops.

All records

101 records
  • PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to execute arbitrary PHP

    HighCVSS 7.5Proof of conceptEPSS 77%

    xoops · horoscope moduleJun 14, 2007

  • PHP remote file inclusion vulnerability in include/wysiwyg/spaw_control.class.php in the icontent 4.5 module for XOOPS allows remote attacke

    MediumCVSS 6.8Proof of conceptEPSS 69%

    xoops · icontent moduleJun 5, 2007

  • PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows remote attackers to

    MediumCVSS 6.8Proof of conceptEPSS 68%

    xoops · xt-conteudo moduleJun 14, 2007

  • PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS allows remote attackers

    MediumCVSS 6.8Proof of conceptEPSS 68%

    xoops · tinycontent moduleJun 14, 2007

  • PHP remote file inclusion vulnerability in admin/editor2/spaw_control.class.php in the Cjay Content 3 module for XOOPS allows remote attacke

    MediumCVSS 6.8Proof of conceptEPSS 63%

    xoops · cjay content moduleJun 14, 2007

  • In install/page_dbsettings.php in the Core distribution of XOOPS 2.5.8.1, unfiltered data passed to CREATE and ALTER SQL queries caused SQL

    CriticalCVSS 9.8No exploitEPSS 1%

    xoops · xoopsJul 12, 2017

  • Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of t

    CriticalCVSS 9.0No exploitEPSS 2%

    xoops · xoopsAug 3, 2023

  • CVE-2007-3289
    34Monitor

    PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote attackers to execut

    HighCVSS 7.5Proof of conceptEPSS 12%

    xoops · wiwimod moduleJun 20, 2007

  • CVE-2007-3222
    32Monitor

    PHP remote file inclusion vulnerability in modify.php in the XFsection 1.07 module for XOOPS allows remote attackers to execute arbitrary PH

    HighCVSS 7.5Proof of conceptEPSS 7%

    xoops · xfsection moduleJun 14, 2007

  • CVE-2008-3296
    32Monitor

    Directory traversal vulnerability in modules/system/admin.php in XOOPS 2.0.18 1 allows remote attackers to include and execute arbitrary loc

    HighCVSS 7.5Proof of conceptEPSS 6%

    xoops · xoopsJul 25, 2008

  • CVE-2007-1974
    32Monitor

    SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as used in Xoops modul

    HighCVSS 7.5Proof of conceptEPSS 6%

    wf-sections · wf-sectionsApr 11, 2007

  • CVE-2007-2370
    31Monitor

    SQL injection vulnerability in index.php in the John Mordo Jobs 2.4 and earlier module for XOOPS allows remote attackers to execute arbitrar

    HighCVSS 7.5Proof of conceptEPSS 3%

    xoops · john mordo jobs moduleApr 30, 2007

  • CVE-2008-0612
    31Monitor

    Directory traversal vulnerability in htdocs/install/index.php in XOOPS 2.0.18 allows remote attackers to include and execute arbitrary local

    HighCVSS 7.5Proof of conceptEPSS 3%

    xoops · xoopsFeb 6, 2008

  • CVE-2007-5188
    31Monitor

    Unspecified vulnerability in the XOOPS uploader class in Xoops 2.0.17.1-RC1 and earlier allows remote attackers to upload arbitrary files vi

    HighCVSS 7.5No exploitEPSS 2%

    xoops · xoopsOct 3, 2007

  • CVE-2007-1838
    31Monitor

    SQL injection vulnerability in view.php in the Friendfinder 3.3 and earlier module for Xoops allows remote attackers to execute arbitrary SQ

    HighCVSS 7.5Proof of conceptEPSS 2%

    xoops · friendfinder moduleApr 2, 2007

  • CVE-2007-1979
    31Monitor

    SQL injection vulnerability in index.php in the PopnupBlog 2.52 and earlier module for Xoops allows remote attackers to execute arbitrary SQ

    HighCVSS 7.5Proof of conceptEPSS 2%

    xoops · xoops popnupblogApr 11, 2007

  • CVE-2007-1846
    31Monitor

    SQL injection vulnerability in index.php in the MyAds 2.04jp and earlier module for Xoops allows remote attackers to execute arbitrary SQL c

    HighCVSS 7.5Proof of conceptEPSS 2%

    xoops · malaika system myads moduleApr 3, 2007

  • CVE-2008-7178
    31Monitor

    Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a ..

    HighCVSS 7.5Proof of conceptEPSS 2%

    xoops · xoopsSep 8, 2009

  • CVE-2007-0377
    31Monitor

    Multiple SQL injection vulnerabilities in Xoops 2.0.16 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in

    HighCVSS 7.5No exploitEPSS 2%

    xoops · xoopsJan 19, 2007

  • CVE-2014-3935
    31Monitor

    SQL injection vulnerability in glossaire-aff.php in the Glossaire module 1.0 for XOOPS allows remote attackers to execute arbitrary SQL comm

    HighCVSS 7.5Proof of conceptEPSS 2%

    xoops · glossaire moduleJun 2, 2014

  • CVE-2007-1976
    31Monitor

    PHP remote file inclusion vulnerability in index.php in the Virii Info 1.10 and earlier module for Xoops allows remote attackers to execute

    HighCVSS 7.5No exploitEPSS 2%

    xoops · xoops virii info moduleApr 11, 2007

  • CVE-2002-0217
    31Monitor

    Cross-site scripting (CSS) vulnerabilities in the Private Message System for XOOPS 1.0 RC1 allow remote attackers to execute Javascript on o

    HighCVSS 7.5No exploitEPSS 2%

    xoops · xoopsMay 16, 2002

  • CVE-2006-4417
    31Monitor

    SQL injection vulnerability in edituser.php in Xoops before 2.0.15 allows remote attackers to execute arbitrary SQL commands via the user_av

    HighCVSS 7.5No exploitEPSS 2%

    xoops · xoopsAug 28, 2006

  • CVE-2009-4698
    31Monitor

    Multiple SQL injection vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to execute arbitrary SQL comman

    HighCVSS 7.5Proof of conceptEPSS 2%

    xoops · xoopsMar 15, 2010

  • CVE-2009-3963
    30Monitor

    Multiple unspecified vulnerabilities in XOOPS before 2.4.0 Final have unknown impact and attack vectors.

    HighCVSS 7.5No exploitEPSS 2%

    xoops · xoopsNov 17, 2009