Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown

CVE-2014-5699

Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The Parallel Kingdom MMO (aka com.silvermoon.client) application @7F070019 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2013-0727

Disclosure Date: April 26, 2013 (last updated October 05, 2023)
Multiple untrusted search path vulnerabilities in Global Mapper 14.1.0 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll or (2) ibfs32.dll file in the current working directory, as demonstrated by a directory that contains a .gmc, .gmg, .gmp, .gms, .gmw, or .opt file.
0
Attacker Value
Unknown

CVE-2007-0784

Disclosure Date: February 06, 2007 (last updated October 04, 2023)
SQL injection vulnerability in login.asp for tPassword in the Raymond BERTHOU script collection (aka RBL - ASP) allows remote attackers to execute arbitrary SQL commands via the (1) User and (2) Password parameters.
0
Attacker Value
Unknown

CVE-2007-0642

Disclosure Date: January 31, 2007 (last updated October 04, 2023)
SQL injection vulnerability in tForum 2.00 in the Raymond BERTHOU script collection (aka RBL - ASP) allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) pass to user_confirm.asp.
0
Attacker Value
Unknown

CVE-2007-0079

Disclosure Date: January 05, 2007 (last updated October 04, 2023)
rblog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) data/admin.mdb or (2) data/rblog.mdb.
0
Attacker Value
Unknown

CVE-2005-1055

Disclosure Date: April 10, 2005 (last updated February 22, 2025)
TowerBlog 0.6 and earlier stores the login data file under the web root, which allows remote attackers to obtain the MD5 checksums of the username and password via a direct request to the _dat/login file.
0
Attacker Value
Unknown

CVE-2003-0830

Disclosure Date: November 17, 2003 (last updated February 22, 2025)
Buffer overflow in marbles 1.0.2 and earlier allows local users to gain privileges via a long HOME environment variable.
0