Каталог CVE

Разработчик: osvdb

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 120

Разработчик: osvdb
Высокая CVSS 7.5

CVE-2007-5065

РасширениеJoomla Joomla
Разработчикosvdb

PHP remote file inclusion vulnerability in admin.slideshow1.php in the Flash Slide Show (com_slideshow) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL…

24.09.2007
Высокая CVSS 7.5

CVE-2007-4777

РасширениеJoomla Joomla
Разработчикosvdb

SQL injection vulnerability in Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to execute arbitrary SQL commands via unspecified vectors, probably related to the archive sectio…

10.09.2007
Средняя CVSS 4.3

CVE-2007-4779

РасширениеJoomla Joomla
Разработчикosvdb

Cross-site scripting (XSS) vulnerability in Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably related to…

10.09.2007
Средняя CVSS 6.8

CVE-2007-4780

РасширениеJoomla Joomla
Разработчикosvdb

Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to obtain sensitive information (the full path) via unspecified vectors, probably involving direct requests to certain PHP scrip…

10.09.2007
Средняя CVSS 6.6

CVE-2007-4781

РасширениеJoomla Joomla
Разработчикosvdb

administrator/index.php in the installer component (com_installer) in Joomla! 1.5 Beta1, Beta2, and RC1 allows remote authenticated administrators to upload arbitrary files to tmp/ via the…

10.09.2007
Высокая CVSS 7.5

CVE-2007-4502

РасширениеJoomla Bibtex
Разработчикosvdb

SQL injection vulnerability in index.php in the BibTeX component (com_jombib) 1.3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the afilter parameter.

23.08.2007
Высокая CVSS 7.5

CVE-2007-4506

РасширениеJoomla Neorecruit
Разработчикosvdb

SQL injection vulnerability in index.php in the NeoRecruit component (com_neorecruit) 1.4 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parame…

23.08.2007
Высокая CVSS 7.5

CVE-2007-4509

РасширениеJoomla Eventlist
Разработчикosvdb

SQL injection vulnerability in index.php in the EventList component (com_eventlist) 0.8 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the did paramet…

23.08.2007
Средняя CVSS 5.0

CVE-2007-4185

РасширениеJoomla Joomla
Разработчикosvdb

Joomla! 1.0.12 allows remote attackers to obtain sensitive information via a direct request for (1) Stat.php (2) OutputFilter.php, (3) OutputCache.php, (4) Modifier.php, (5) Reader.php, and…

08.08.2007
Средняя CVSS 6.8

CVE-2007-4186

РасширениеJoomla Tour De France Pool
Разработчикosvdb

PHP remote file inclusion vulnerability in admin.tour_toto.php in the Tour de France Pool (com_tour_toto) 1.0.1 module for Joomla! allows remote attackers to execute arbitrary PHP code via…

08.08.2007
Средняя CVSS 4.3

CVE-2007-4189

РасширениеJoomla Joomla\!
Разработчикosvdb

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.13 (aka Sunglow) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in the (1) c…

08.08.2007
Средняя CVSS 4.3

CVE-2007-4190

РасширениеJoomla Joomla\!
Разработчикosvdb

CRLF injection vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to inject arbitrary HTTP headers and probably conduct HTTP response splitting attacks via CRLF se…

08.08.2007
Высокая CVSS 7.5

CVE-2007-4046

РасширениеJoomla Pony Gallery
Разработчикosvdb

SQL injection vulnerability in index.php in the Pony Gallery (com_ponygallery) 1.5 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid…

27.07.2007
Высокая CVSS 7.5

CVE-2007-3932

РасширениеJoomla Expose
Разработчикosvdb

uploadimg.php in the Expose RC35 and earlier (com_expose) component for Joomla! sends an error message but does not exit when it detects an attempt to upload a non-JPEG file, which allows r…

21.07.2007
Средняя CVSS 6.8

CVE-2007-3130

РасширениеJoomla Jd-wiki
Разработчикosvdb

Multiple PHP remote file inclusion vulnerabilities in the OpenWiki (formerly JD-Wiki) component (com_jd-wiki) 1.0.2, and possibly earlier, for Joomla! allow remote attackers to execute arbi…

08.06.2007
Высокая CVSS 7.5

CVE-2007-2933

РасширениеPhil-a-form Phil-a-form
Разработчикosvdb

SQL injection vulnerability in index.php in the Phil-a-Form (com_philaform) 1.2.0.0 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the form_…

31.05.2007
Высокая CVSS 7.5

CVE-2007-2792

РасширениеCom Yanc Com Yanc
Разработчикosvdb

SQL injection vulnerability in the Yet another Newsletter Component (aka YaNC or com_yanc) component before 1.5 beta 3 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL…

22.05.2007
Средняя CVSS 6.8

CVE-2007-2319

Разработчикosvdb

PHP remote file inclusion vulnerability in the AutoStand 1.1 and earlier module for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path pa…

26.04.2007