Show filters
14 Total Results
Displaying 11-14 of 14
Sort by:
Attacker Value
Unknown

CVE-2014-4306

Disclosure Date: June 18, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in logs-x.php in WebTitan before 4.04 allows remote attackers to read arbitrary files via a .. (dot dot) in the logfile parameter in a download action.
0
Attacker Value
Unknown

CVE-2011-4640

Disclosure Date: October 08, 2012 (last updated October 05, 2023)
Directory traversal vulnerability in logs-x.php in SpamTitan WebTitan before 3.60 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the fname parameter in a view action.
0
Attacker Value
Unknown

CVE-2011-4639

Disclosure Date: October 08, 2012 (last updated October 05, 2023)
The (1) Traceroute and (2) Ping implementations in tools.php in SpamTitan WebTitan before 3.60 allow remote authenticated users to execute arbitrary commands via shell metacharacters in an argument, as demonstrated by an && (ampersand ampersand) sequence.
0
Attacker Value
Unknown

CVE-2011-4638

Disclosure Date: October 08, 2012 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in SpamTitan WebTitan before 3.60 allow remote attackers to execute arbitrary SQL commands via (1) the username parameter to login-x.php, and allow remote authenticated users to execute arbitrary SQL commands via the (2) bldomain, (3) wldomain, or (4) temid parameter to urls-x.php.
0