Show filters
22 Total Results
Displaying 11-20 of 22
Sort by:
Attacker Value
Unknown

Alzip Stack Overflow Vulnerability

Disclosure Date: December 21, 2018 (last updated November 27, 2024)
Alzip 10.76.0.0 and earlier is vulnerable to a stack overflow caused by improper bounds checking. By persuading a victim to open a specially-crafted LZH archive file, a attacker could execute arbitrary code execution.
0
Attacker Value
Unknown

CVE-2018-10027

Disclosure Date: May 17, 2018 (last updated November 26, 2024)
ESTsoft ALZip before 10.76 allows local users to execute arbitrary code via creating a malicious .DLL file and installing it in a specific directory: %PROGRAMFILES%\ESTsoft\ALZip\Formats, %PROGRAMFILES%\ESTsoft\ALZip\Coders, %PROGRAMFILES(X86)%\ESTsoft\ALZip\Formats, or %PROGRAMFILES(X86)%\ESTsoft\ALZip\Coders.
0
Attacker Value
Unknown

CVE-2017-11323

Disclosure Date: August 19, 2017 (last updated November 26, 2024)
Stack-based buffer overflow in ESTsoft ALZip 8.51 and earlier allows remote attackers to execute arbitrary code via a crafted MS-DOS device file, as demonstrated by use of "AUX" as the initial substring of a filename.
Attacker Value
Unknown

CVE-2014-8494

Disclosure Date: November 03, 2014 (last updated October 05, 2023)
ESTsoft ALUpdate 8.5.1.0.0 uses weak permissions (Users: Full Control) for the (1) AlUpdate folder and (2) AlUpdate.exe, which allows local users to gain privileges via a Trojan horse file.
0
Attacker Value
Unknown

CVE-2014-4035

Disclosure Date: June 11, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in booking_details.php in Best Soft Inc. (BSI) Advance Hotel Booking System 2.0 allows remote attackers to inject arbitrary web script or HTML via the title parameter.
0
Attacker Value
Unknown

CVE-2010-5211

Disclosure Date: September 06, 2012 (last updated October 05, 2023)
Untrusted search path vulnerability in ALSee 6.20.0.1 allows local users to gain privileges via a Trojan horse patchani.dll file in the current working directory, as demonstrated by a directory that contains a .ani, .bmp, .cal, .hdp, .jpe, .mac, .pbm, .pcx, .pgm, .png, .psd, .ras, .tga, or .tiff file. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2012-0315

Disclosure Date: February 22, 2012 (last updated October 04, 2023)
Untrusted search path vulnerability in ALFTP before 5.31 allows local users to gain privileges via a Trojan horse executable file in a directory that is accessed for reading an extensionless file, as demonstrated by executing the README.exe file when a user attempts to access the README file.
0
Attacker Value
Unknown

CVE-2010-4814

Disclosure Date: July 08, 2011 (last updated October 04, 2023)
SQL injection vulnerability in index1.php in Best Soft Inc. (BSI) Advance Hotel Booking System 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.
0
Attacker Value
Unknown

CVE-2011-1336

Disclosure Date: July 07, 2011 (last updated October 04, 2023)
Buffer overflow in ALZip 8.21 and earlier allows remote attackers to execute arbitrary code via a crafted mim file.
0
Attacker Value
Unknown

CVE-2008-2702

Disclosure Date: June 13, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in the FTP client in ALTools ESTsoft ALFTP 4.1 beta 2 and 5.0 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345. NOTE: this can be leveraged for code execution by writing to a Startup folder.
0