Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown

CVE-2006-2887

Disclosure Date: June 07, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in myNewsletter 1.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the UserName parameter in (1) validatelogin.asp or (2) adminlogin.asp.
0
Attacker Value
Unknown

CVE-2006-2648

Disclosure Date: May 30, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in perform_search.asp for ASPBB 0.52 and earlier allows remote attackers to inject arbitrary HTML or web script via the search parameter.
0
Attacker Value
Unknown

CVE-2006-2497

Disclosure Date: May 20, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in AspBB 0.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) action parameter to default.asp or (2) get parameter to profile.asp.
0
Attacker Value
Unknown

CVE-2005-4589

Disclosure Date: December 30, 2005 (last updated February 22, 2025)
Spb Kiosk Engine 1.0.0.1 stores the administrator's passcode in the registry in plaintext, which allows local users to obtain the passcode.
0
Attacker Value
Unknown

CVE-2005-4590

Disclosure Date: December 30, 2005 (last updated February 22, 2025)
Spb Kiosk Engine 1.0.0.1 allows local users to bypass restrictions on allowed applications via (1) removable media containing a program that will execute because of the autorun setting and (2) applications that are able to invoke other applications, as demonstrated by a file: URL specifying a .exe file.
0
Attacker Value
Unknown

CVE-2005-4446

Disclosure Date: December 21, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in index.asp in ASPBite 8.x allows remote attackers to inject arbitrary web script or HTML via the strSearch parameter.
0
Attacker Value
Unknown

CVE-2005-4259

Disclosure Date: December 15, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in ASPBB 0.4 allow remote attackers to execute arbitrary SQL commands via the (1) TID parameter in topic.asp, (2) FORUM_ID parameter in forum.asp, and (3) PROFILE_ID parameter in profile.asp. NOTE: the provenance of this issue is unknown; the details are obtained solely from the BID.
0
Attacker Value
Unknown

CVE-2002-1734

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
NewsPro 1.01 allows remote attackers to gain unauthorized administrator access by setting their authentication cookie to "logged,true".
0