Show filters
30 Total Results
Displaying 11-20 of 30
Sort by:
Attacker Value
Unknown

CVE-2009-0963

Disclosure Date: March 19, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in PHPRunner 4.2, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the SearchField parameter to (1) UserView_list.php, (2) orders_list.php, (3) users_list.php, and (4) Administrator_list.php.
0
Attacker Value
Unknown

CVE-2009-0964

Disclosure Date: March 19, 2009 (last updated February 15, 2024)
UserView_list.php in PHPRunner 4.2, and possibly earlier, stores passwords in cleartext in the database, which allows attackers to gain privileges. NOTE: this can be leveraged with a separate SQL injection vulnerability to obtain passwords remotely without authentication.
Attacker Value
Unknown

CVE-2008-0604

Disclosure Date: February 06, 2008 (last updated October 04, 2023)
The LDAP authentication feature in XLight FTP Server before 2.83, when used with some unspecified LDAP servers, does not check for blank passwords, which allows remote attackers to bypass intended access restrictions.
0
Attacker Value
Unknown

CVE-2007-4314

Disclosure Date: August 13, 2007 (last updated October 04, 2023)
pixlie.php in Pixlie 1.7 allows remote attackers to trigger the reading and JPEG image processing of files in a remote directory tree via a URL in the root parameter. NOTE: this can be leveraged for traffic amplification or other denial of service.
0
Attacker Value
Unknown

CVE-2007-3835

Disclosure Date: July 17, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Ex Libris MetaLib 3.13 and 4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to a resource id that can be discovered through a search.
0
Attacker Value
Unknown

CVE-2007-3834

Disclosure Date: July 17, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Ex Libris ALEPH allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to a URL that can be discovered through a keyword search. NOTE: this may be related to the MetaLib XSS issue, CVE-2007-3835.
0
Attacker Value
Unknown

CVE-2006-5956

Disclosure Date: November 17, 2006 (last updated October 04, 2023)
XLineSoft PHPRunner 3.1 stores the (1) database server name, (2) database names, (3) usernames, and (4) passwords in plaintext in %WINDIR%\PHPRunner.ini, which allows local users to obtain sensitive information by reading the file.
0
Attacker Value
Unknown

CVE-2006-5792

Disclosure Date: November 07, 2006 (last updated October 04, 2023)
Unspecified vulnerability in XLink Omni-NFS Enterprise allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by vd_xlink2.pm, an "Omni-NFS Enterprise remote exploit." NOTE: this is probably a different vulnerability than CVE-2006-5780. As of 20061107, this disclosure has no actionable information. However, since it is from a reliable researcher, it is being assigned a CVE identifier for tracking purposes.
0
Attacker Value
Unknown

CVE-2006-5780

Disclosure Date: November 07, 2006 (last updated October 04, 2023)
Stack-based buffer overflow in nfsd.exe in XLink Omni-NFS Server 5.2 allows remote attackers to execute arbitrary code via a crafted TCP packet to port 2049 (nfsd), as demonstrated by vd_xlink.pm.
0
Attacker Value
Unknown

CVE-2005-3178

Disclosure Date: October 07, 2005 (last updated February 22, 2025)
Buffer overflow in xloadimage 4.1 and earlier, and xli, might allow user-assisted attackers to execute arbitrary code via a long title name in a NIFF file, which triggers the overflow during (1) zoom, (2) reduce, or (3) rotate operations.
0