Vulnerability index

Browse CVEs

65 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wiwimod Module HIGH 7.5
CVE-2007-3289EPSS 12%

PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote attackers to execute arbitra…

No fix yet
Fix from $1,950 2007-06-20
Horoscope Module HIGH 7.5
CVE-2007-3236EPSS 77%

PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to execute arbitrary PHP code via…

No fix yet
Fix from $1,950 2007-06-15
Tinycontent Module MEDIUM 6.8
CVE-2007-3237EPSS 68%

PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS allows remote attackers to execu…

No fix yet
Fix from $1,600 2007-06-15
Xfsection Module HIGH 7.5
CVE-2007-3222EPSS 7%

PHP remote file inclusion vulnerability in modify.php in the XFsection 1.07 module for XOOPS allows remote attackers to execute arbitrary PHP code vi…

No fix yet
Fix from $1,950 2007-06-14
Cjay Content Module MEDIUM 6.8
CVE-2007-3220EPSS 63%

PHP remote file inclusion vulnerability in admin/editor2/spaw_control.class.php in the Cjay Content 3 module for XOOPS allows remote attackers to exe…

No fix yet
Fix from $1,600 2007-06-14
Xt Conteudo Module MEDIUM 6.8
CVE-2007-3221EPSS 68%

PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows remote attackers to execute a…

No fix yet
Fix from $1,600 2007-06-14
Icontent Module MEDIUM 6.8
CVE-2007-3057EPSS 69%

PHP remote file inclusion vulnerability in include/wysiwyg/spaw_control.class.php in the icontent 4.5 module for XOOPS allows remote attackers to exe…

No fix yet
Fix from $1,600 2007-06-06
Myconference Module HIGH 7.5
CVE-2007-2737

SQL injection vulnerability in index.php in the MyConference 1.0 module for Xoops allows remote attackers to execute arbitrary SQL commands via the c…

Mitigation only
Fix from $1,950 2007-05-17
Xoops Glossaire Module HIGH 7.5
CVE-2007-2738

SQL injection vulnerability in glossaire-p-f.php in the Glossaire 1.7 and earlier module for Xoops allows remote attackers to execute arbitrary SQL c…

Fix: after 1.7
Fix from $1,950 2007-05-17
Wfquotes Module HIGH 7.5
CVE-2007-2571

SQL injection vulnerability in index.php in the wfquotes 1.0 0 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the c p…

Fix: after 1.0.0
Fix from $1,950 2007-05-09
Flashgames Module HIGH 7.5
CVE-2007-2543

SQL injection vulnerability in game.php in the Flashgames 1.0.1 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the li…

No fix yet
Fix from $1,950 2007-05-09
John Mordo Jobs Module HIGH 7.5
CVE-2007-2370

SQL injection vulnerability in index.php in the John Mordo Jobs 2.4 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL com…

Fix: after 2.4
Fix from $1,950 2007-04-30
Xoops Popnupblog HIGH 7.5
CVE-2007-1979

SQL injection vulnerability in index.php in the PopnupBlog 2.52 and earlier module for Xoops allows remote attackers to execute arbitrary SQL command…

Fix: after 2.52
Fix from $1,950 2007-04-12
Xoops Virii Info Module HIGH 7.5
CVE-2007-1976

PHP remote file inclusion vulnerability in index.php in the Virii Info 1.10 and earlier module for Xoops allows remote attackers to execute arbitrary…

Fix: after 1.10
Fix from $1,950 2007-04-12
Rha7 Downloads Module HIGH 7.5
CVE-2007-1960

SQL injection vulnerability in visit.php in the Rha7 Downloads (rha7downloads) 1.0 module for XOOPS, and possibly other versions up to 1.10, allows r…

No fix yet
Fix from $1,950 2007-04-11
Wf Snippets HIGH 7.5
CVE-2007-1962

SQL injection vulnerability in index.php in the WF-Snippets 1.02 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL comman…

Fix: after 1.02
Fix from $1,950 2007-04-11
Malaika System Myads Module HIGH 7.5
CVE-2007-1846

SQL injection vulnerability in index.php in the MyAds 2.04jp and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands v…

Fix: after 2.04
Fix from $1,950 2007-04-03
Repository Module HIGH 7.5
CVE-2007-1847

SQL injection vulnerability in viewcat.php in the Repository module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid p…

No fix yet
Fix from $1,950 2007-04-03
Friendfinder Module HIGH 7.5
CVE-2007-1838

SQL injection vulnerability in view.php in the Friendfinder 3.3 and earlier module for Xoops allows remote attackers to execute arbitrary SQL command…

Fix: after 3.3
Fix from $1,950 2007-04-03
Core Module HIGH 7.5
CVE-2007-1814

SQL injection vulnerability in viewcat.php in the Core module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid paramet…

No fix yet
Fix from $1,950 2007-04-02
Library Module HIGH 7.5
CVE-2007-1815

SQL injection vulnerability in viewcat.php in the Library module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid para…

No fix yet
Fix from $1,950 2007-04-02
Tutoriais Module HIGH 7.5
CVE-2007-1816

SQL injection vulnerability in viewcat.php in the Tutoriais module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid pa…

No fix yet
Fix from $1,950 2007-04-02
Xoops HIGH 7.5
CVE-2007-0377

Multiple SQL injection vulnerabilities in Xoops 2.0.16 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in kernel/gr…

No fix yet
Fix from $1,950 2007-01-19
Xoops MEDIUM 6.8
CVE-2006-5810

Cross-site scripting (XSS) vulnerability in modules/wfdownloads/newlist.php in XOOPS 1.0 allows remote attackers to inject arbitrary web script or HT…

No fix yet
Fix from $1,600 2006-11-08
Xoops Rmsoft Gallery System MEDIUM 6.8
CVE-2006-5532

Cross-site scripting (XSS) vulnerability in rmgs/images.php in RMSOFT Gallery System 2.0 allows remote attackers to inject arbitrary web script or HT…

No fix yet
Fix from $1,600 2006-10-26
Xoops HIGH 7.5
CVE-2006-4417

SQL injection vulnerability in edituser.php in Xoops before 2.0.15 allows remote attackers to execute arbitrary SQL commands via the user_avatar para…

Fix: after 2.0.14
Fix from $1,950 2006-08-28
Xoops Glossaire Module MEDIUM 5.1
CVE-2006-3363

PHP remote file inclusion vulnerability in index.php in the Glossaire module 1.7 for Xoops allows remote attackers to execute arbitrary PHP code via …

No fix yet
Fix from $1,600 2006-07-06
Xoops MEDIUM 5.1
CVE-2006-2516EPSS 6%

mainfile.php in XOOPS 2.0.13.2 and earlier, when register_globals is enabled, allows remote attackers to overwrite variables such as $xoopsOption['no…

Fix: after 2.0.13.2
Fix from $1,600 2006-05-22
Wf Downloads HIGH 7.5
CVE-2005-3681

SQL injection vulnerability in viewcat.php in XOOPS WF-Downloads module 2.05 allows remote attackers to execute arbitrary SQL commands via the list p…

No fix yet
Fix from $1,950 2005-11-18
Xoops MEDIUM 6.4
CVE-2005-3680

Directory traversal vulnerability in editor_registry.php in XOOPS 2.2.3 allows remote attackers to read or include arbitrary local files via a .. (do…

No fix yet
Fix from $1,600 2005-11-18