Show filters
104 Total Results
Displaying 101-104 of 104
Sort by:
Attacker Value
Unknown
CVE-2011-0009
Disclosure Date: January 25, 2011 (last updated October 04, 2023)
Best Practical Solutions RT 3.x before 3.8.9rc2 and 4.x before 4.0.0rc4 uses the MD5 algorithm for password hashes, which makes it easier for context-dependent attackers to determine cleartext passwords via a brute-force attack on the database.
0
Attacker Value
Unknown
CVE-2009-4060
Disclosure Date: November 24, 2009 (last updated October 04, 2023)
SQL injection vulnerability in includes/content/viewProd.inc.php in CubeCart before 4.3.7 remote attackers to execute arbitrary SQL commands via the productId parameter.
0
Attacker Value
Unknown
CVE-2008-3502
Disclosure Date: August 06, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Best Practical Solutions RT 3.0.0 through 3.6.6 allows remote authenticated users to cause a denial of service (CPU or memory consumption) via unspecified vectors related to the Devel::StackTrace module for Perl.
0
Attacker Value
Unknown
CVE-2006-0922
Disclosure Date: February 28, 2006 (last updated February 22, 2025)
CubeCart 3.0 through 3.6 does not properly check authorization for an administration session because of a missing auth.inc.php include, which results in an absolute path traversal vulnerability in FileUpload in connector.php (aka upload.php) that allows remote attackers to upload arbitrary files via a modified CurrentFolder parameter in a direct request to admin/filemanager/upload.php.
0