RSS   Vulnerabilities for 'Owl intranet engine'   RSS

2006-03-10
 
CVE-2006-1149

 

 
PHP remote file inclusion vulnerability in lib/OWL_API.php in OWL Intranet Engine 0.82, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the xrms_file_root parameter, which is not initialized before use.

 
2005-05-02
 
CVE-2005-0265

 

 
Multiple SQL injection vulnerabilities in browse.php in OWL 0.7 and 0.8 allow remote attackers to execute arbitrary SQL commands via the (1) parent or (2) sortposted parameter.

 
 
CVE-2005-0264

 

 
Multiple cross-site scripting (XSS) vulnerabilities in browse.php in OWL 0.7 and 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) expand or (2) order parameter.

 
2003-05-21
 
CVE-2003-0341

 

 
Cross-site scripting (XSS) vulnerability in Owl Intranet Engine 0.71 and earlier allows remote attackers to insert arbitrary script via the Search field.

 

 >>> Vendor: OWL 2 Products
Owl intranet engine
Intranet knowledgebase


Copyright 2024, cxsecurity.com

 

Back to Top