Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown
CVE-2007-6360
Disclosure Date: December 15, 2007 (last updated October 04, 2023)
Unspecified vulnerability in the Sun eXtended System Control Facility (XSCF) Control Package (XCP) firmware before 1050 on SPARC Enterprise M4000, M5000, M8000, and M9000 servers allows remote attackers to cause a denial of service (reboot) via (1) telnet, (2) ssh, or (3) http network traffic that triggers memory exhaustion.
0
Attacker Value
Unknown
CVE-2006-3394
Disclosure Date: July 06, 2006 (last updated October 04, 2023)
SQL injection vulnerability in the files mod in index.php in BXCP 0.3.0.4 allows remote attackers to execute arbitrary SQL commands via the where parameter in a view action.
0
Attacker Value
Unknown
CVE-2006-0821
Disclosure Date: February 21, 2006 (last updated February 22, 2025)
SQL injection vulnerability in index.php in BXCP 0.299 allows remote attackers to execute arbitrary SQL commands via the tid parameter.
0
Attacker Value
Unknown
CVE-2005-3650
Disclosure Date: November 17, 2005 (last updated February 22, 2025)
The CodeSupport.ocx ActiveX control, as used by Sony to uninstall the First4Internet XCP DRM, has "safe for scripting" enabled, which allows remote attackers to execute arbitrary code by calling vulnerable functions such as RebootMachine, IsAdministrator, and ExecuteCode.
0
Attacker Value
Unknown
CVE-2005-3474
Disclosure Date: November 03, 2005 (last updated February 22, 2025)
The aries.sys driver in Sony First4Internet XCP DRM software hides any file, registry key, or process with a name that starts with "$sys$", which allows attackers to hide activities on a system that uses XCP.
0