Show filters
61 Total Results
Displaying 11-20 of 61
Sort by:
Attacker Value
Unknown

CVE-2014-5834

Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The Solitaire Deluxe (aka com.gosub60.solfree2) application 2.8.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2011-3725

Disclosure Date: September 23, 2011 (last updated October 04, 2023)
DeluxeBB 1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by header_html.php.
0
Attacker Value
Unknown

CVE-2010-4151

Disclosure Date: November 03, 2010 (last updated October 04, 2023)
SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.
0
Attacker Value
Unknown

CVE-2010-1859

Disclosure Date: May 07, 2010 (last updated October 04, 2023)
SQL injection vulnerability in newpost.php in DeluxeBB 1.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the membercookie cookie when adding a new thread.
0
Attacker Value
Unknown

CVE-2009-4467

Disclosure Date: December 30, 2009 (last updated October 04, 2023)
misc.php in DeluxeBB 1.3 allows remote attackers to register accounts without a valid email address via a valemail action with the valmem set to a pre-assigned user ID, which is visible from a memberlist action.
0
Attacker Value
Unknown

CVE-2009-4468

Disclosure Date: December 30, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in misc.php in DeluxeBB 1.3 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
0
Attacker Value
Unknown

CVE-2009-4465

Disclosure Date: December 30, 2009 (last updated October 04, 2023)
DeluxeBB 1.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user and configuration information, log data, and gain administrative access via a direct request to scripts in (1) templates/ including (2) templates/deluxe/admincp/, (3) templates/corporate/admincp/, and (4) templates/blue/admincp/; (5) images/; (6) logs/ including (7) logs/cp.php; (8) wysiwyg/; (9) docs/; (10) classes/; (11) lang/; and (12) settings/.
0
Attacker Value
Unknown

CVE-2009-4466

Disclosure Date: December 30, 2009 (last updated October 04, 2023)
DeluxeBB 1.3 allows remote attackers to obtain sensitive information via a crafted page parameter to misc.php, which reveals the installation path in an error message. NOTE: this issue might be resultant from improperly controlled computation in tools.php that leads to a denial of service (CPU or memory consumption).
0
Attacker Value
Unknown

CVE-2008-6926

Disclosure Date: August 10, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Module for cPanel allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the scriptpath_show parameter in a GoAhead action. NOTE: this issue only crosses privilege boundaries when security settings such as disable_functions and safe_mode are active, since exploitation requires uploading of executable code to a home directory.
0
Attacker Value
Unknown

CVE-2008-6843

Disclosure Date: July 02, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in Fantastico, as used with cPanel 11.x, allows remote attackers to read arbitrary files via a .. (dot dot) in the sup3r parameter.
0