Show filters
23 Total Results
Displaying 11-20 of 23
Sort by:
Attacker Value
Unknown

CVE-2021-38146

Disclosure Date: November 22, 2021 (last updated February 23, 2025)
The File Download API in Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read arbitrary files via absolute path traversal in the SearchString JSON field in /home/download POST data.
Attacker Value
Unknown

CVE-2021-34813

Disclosure Date: June 16, 2021 (last updated February 22, 2025)
Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backup from the homeserver) because olm_pk_decrypt has a stack-based buffer overflow. Remote code execution might be possible for some nonstandard build configurations.
Attacker Value
Unknown

CVE-2011-5135

Disclosure Date: August 30, 2012 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in the save_connection function in lib/lib.iotask.php in the iotask module in DoceboLMS 4.0.4 and earlier allow remote authenticated users with admin or teacher privileges to execute arbitrary SQL commands via the (1) coursereportuiconfig[name] or (2) coursereportuiconfig[description] parameters to index.php.
0
Attacker Value
Unknown

CVE-2010-5011

Disclosure Date: November 02, 2011 (last updated October 04, 2023)
SQL injection vulnerability in schoolmv2/html/studentmain.php in SchoolMation 2.3 allows remote attackers to execute arbitrary SQL commands via the session parameter.
0
Attacker Value
Unknown

CVE-2010-5010

Disclosure Date: November 02, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in schoolmv2/html/studentmain.php in SchoolMation 2.3 allows remote attackers to inject arbitrary web script or HTML via the session parameter.
0
Attacker Value
Unknown

CVE-2011-3726

Disclosure Date: September 23, 2011 (last updated October 04, 2023)
DoceboLMS 4.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by views/dummy/show.php and certain other files.
0
Attacker Value
Unknown

CVE-2007-6250

Disclosure Date: January 09, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in AOL AOLMediaPlaybackControl (AOLMediaPlaybackControl.exe), as used by AmpX ActiveX control (AmpX.dll), might allow remote attackers to execute arbitrary code via the AppendFileToPlayList method.
0
Attacker Value
Unknown

CVE-2006-6857

Disclosure Date: December 31, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in modules/credits/credits.php in Docebo LMS allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
0
Attacker Value
Unknown

CVE-2006-3143

Disclosure Date: June 22, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in icue_login.asp in Maximus SchoolMAX 4.0.1 and earlier iCue and iParent applications allows remote attackers to inject arbitrary web script or HTML via the error_msg parameter.
0
Attacker Value
Unknown

CVE-2006-2668

Disclosure Date: May 30, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Docebo LMS 2.05 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) modules/credits/business.php, (2) modules/credits/credits.php, or (3) modules/credits/help.php.
0