Show filters
157 Total Results
Displaying 11-20 of 157
Sort by:
Attacker Value
Unknown

CVE-2008-6475

Disclosure Date: March 16, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the guestbook component (components/guestbook/guestbook.php) in Drake CMS 0.4.11 and earlier allows remote attackers to execute arbitrary SQL commands via the Via HTTP header (HTTP_VIA) to index.php.
0
Attacker Value
Unknown

CVE-2008-1371

Disclosure Date: March 18, 2008 (last updated October 04, 2023)
Absolute path traversal vulnerability in install/index.php in Drake CMS 0.4.11 RC8 allows remote attackers to read and execute arbitrary files via a full pathname in the d_root parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2008-0595

Disclosure Date: February 29, 2008 (last updated February 01, 2024)
dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a method call with a NULL interface.
0
Attacker Value
Unknown

CVE-2007-6695

Disclosure Date: February 01, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in Drake CMS 0.4.9 allows remote attackers to inject arbitrary web script or HTML via the option parameter.
0
Attacker Value
Unknown

CVE-2007-6284

Disclosure Date: January 12, 2008 (last updated October 04, 2023)
The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent attackers to cause a denial of service (infinite loop) via XML containing invalid UTF-8 sequences.
0
Attacker Value
Unknown

CVE-2007-5116

Disclosure Date: November 07, 2007 (last updated October 04, 2023)
Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attackers to execute arbitrary code by switching from byte to Unicode (UTF) characters in a regular expression.
0
Attacker Value
Unknown

CVE-2007-2618

Disclosure Date: May 11, 2007 (last updated October 04, 2023)
CRLF injection vulnerability in index.php in Drake CMS 0.4.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the lang parameter. NOTE: Drake CMS has only a beta version available, and the vendor has previously stated "We do not consider security reports valid until the first official release of Drake CMS."
0
Attacker Value
Unknown

CVE-2007-1352

Disclosure Date: April 06, 2007 (last updated October 04, 2023)
Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, which results in a heap overflow.
0
Attacker Value
Unknown

CVE-2007-1351

Disclosure Date: April 06, 2007 (last updated October 04, 2023)
Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflow.
0
Attacker Value
Unknown

CVE-2007-1849

Disclosure Date: April 03, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in 404.php in Drake CMS allows remote attackers to include and execute arbitrary local arbitrary files via a .. (dot dot) in the d_private parameter. NOTE: some of these details are obtained from third party information. NOTE: Drake CMS has only a beta version available, and the vendor has previously stated "We do not consider security reports valid until the first official release of Drake CMS."
0