Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown

CVE-2010-2477

Disclosure Date: November 06, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the paste.httpexceptions implementation in Paste before 1.7.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving a 404 status code, related to (1) paste.urlparser.StaticURLParser, (2) paste.urlparser.PkgResourcesParser, (3) paste.urlmap.URLMap, and (4) HTTPNotFound.
0
Attacker Value
Unknown

CVE-2009-1404

Disclosure Date: April 24, 2009 (last updated October 04, 2023)
SQL injection vulnerability in admin.php in PastelCMS 0.8.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user (Username) parameter.
0
Attacker Value
Unknown

CVE-2009-1405

Disclosure Date: April 24, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in PastelCMS 0.8.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the set_lng parameter.
0
Attacker Value
Unknown

CVE-2008-6724

Disclosure Date: April 17, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.pl in Perl Nopaste 1.0 allows remote attackers to inject arbitrary web script or HTML via the language parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2009-1245

Disclosure Date: April 06, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in the insert_to_pastebin function in php/cccp-admin/inc/functions.php in CCCP Community Clan Portal Pastebin before 2.80 allow remote attackers to execute arbitrary SQL commands via the (1) subject, (2) language, and (3) nickname parameters to php/cccp-pages/submit.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2007-0862

Disclosure Date: February 09, 2007 (last updated November 08, 2023)
PHP remote file inclusion vulnerability in index.php in gnopaste 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code via the GNP_REAL_PATH parameter. NOTE: CVE and a third party dispute this issue, since GNP_REAL_PATH is a constant, not a variable
0
Attacker Value
Unknown

CVE-2006-2834

Disclosure Date: June 06, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in includes/common.php in gnopaste 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.
0