Show filters
30 Total Results
Displaying 1-10 of 30
Sort by:
Attacker Value
Unknown

CVE-2024-0737

Disclosure Date: January 19, 2024 (last updated January 27, 2024)
A vulnerability classified as problematic was found in Xlightftpd Xlight FTP Server 1.1. This vulnerability affects unknown code of the component Login. The manipulation of the argument user leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-251560.
Attacker Value
Unknown

CVE-2008-10002

Disclosure Date: March 05, 2023 (last updated October 12, 2023)
A vulnerability has been found in cfire24 ajaxlife up to 0.3.2 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 0.3.3 is able to address this issue. The patch is identified as 9fb53b67312fe3f4336e01c1e3e1bedb4be0c1c8. It is recommended to upgrade the affected component. VDB-222286 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-28998

Disclosure Date: May 23, 2022 (last updated October 07, 2023)
Xlight FTP v3.9.3.2 was discovered to contain a stack-based buffer overflow which allows attackers to leak sensitive information via crafted code.
Attacker Value
Unknown

CVE-2022-24177

Disclosure Date: March 10, 2022 (last updated October 07, 2023)
A cross-site scripting (XSS) vulnerability in the component cgi-bin/ej.cgi of Ex libris ALEPH 500 v18.1 and v20 allows attackers to execute arbitrary web scripts or HTML.
Attacker Value
Unknown

CVE-2021-40084

Disclosure Date: August 25, 2021 (last updated February 23, 2025)
opensysusers through 0.6 does not safely use eval on files in sysusers.d that may contain shell metacharacters. For example, it allows command execution via a crafted GECOS field whereas systemd-sysusers (a program with the same specification) does not do that.
Attacker Value
Unknown

CVE-2020-10587

Disclosure Date: March 14, 2020 (last updated November 27, 2024)
antiX and MX Linux allow local users to achieve root access via "persist-config --command /bin/sh" because of the Sudo configuration.
Attacker Value
Unknown

CVE-2014-3719

Disclosure Date: January 30, 2020 (last updated February 21, 2025)
Multiple SQL injection vulnerabilities in cgi-bin/review_m.cgi in Ex Libris ALEPH 500 (Integrated library management system) 18.1 and 20 allow remote attackers to execute arbitrary SQL commands via the (1) find, (2) lib, or (3) sid parameter.
Attacker Value
Unknown

CVE-2014-3718

Disclosure Date: January 30, 2020 (last updated February 21, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/tag_m.cgi in Ex Libris ALEPH 500 (Integrated library management system) 18.1 and 20 allow remote attackers to inject arbitrary web script or HTML via the (1) find, (2) lib, or (3) sid parameter.
Attacker Value
Unknown

CVE-2010-2695

Disclosure Date: July 12, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in the SFTP/SSH2 virtual server in Xlight FTP Server 3.5.0, 3.5.5, and possibly other versions before 3.6 allows remote authenticated users to read, overwrite, or delete arbitrary files via .. (dot dot) sequences in the (1) ls, (2) rm, (3) rename, and other unspecified commands.
0
Attacker Value
Unknown

CVE-2009-4795

Disclosure Date: April 22, 2010 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Xlight FTP Server before 3.2.1, when ODBC authentication is enabled, allow remote attackers to execute arbitrary SQL commands via the (1) USER (aka username) or (2) PASS (aka password) command.
0