Show filters
140 Total Results
Displaying 111-120 of 140
Sort by:
Attacker Value
Unknown
CVE-2015-2861
Disclosure Date: June 18, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in Vesta Control Panel before 0.9.8-14 allows remote attackers to hijack the authentication of arbitrary users.
0
Attacker Value
Unknown
CVE-2014-8868
Disclosure Date: December 07, 2014 (last updated October 05, 2023)
EntryPass N5200 Active Network Control Panel does not properly restrict access, which allows remote attackers to obtain the administrator username and password, and possibly other sensitive information, via a request to /4.
0
Attacker Value
Unknown
CVE-2014-9303
Disclosure Date: December 07, 2014 (last updated October 05, 2023)
EntryPass N5200 Active Network Control Panel allows remote attackers to read device memory and obtain the administrator username and password via a URL starting with an ASCII character o through z or A through D, different vectors than CVE-2014-8868.
0
Attacker Value
Unknown
CVE-2014-2531
Disclosure Date: October 21, 2014 (last updated October 05, 2023)
SQL injection vulnerability in xhr.php in InterWorx Web Control Panel (aka InterWorx Hosting Control Panel and InterWorx-CP) before 5.0.14 build 577 allows remote authenticated users to execute arbitrary SQL commands via the i parameter in a search action to the (1) NodeWorx , (2) SiteWorx, or (3) Resellers interface, as demonstrated by the "or" key in a pgn8state object in an i object in a JSON object.
0
Attacker Value
Unknown
CVE-2014-2035
Disclosure Date: February 27, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in xhr.php in InterWorx Web Control Panel (aka InterWorx Hosting Control Panel and InterWorx-CP) before 5.0.13 build 574 allows remote attackers to inject arbitrary web script or HTML via the i parameter.
0
Attacker Value
Unknown
CVE-2008-6950
Disclosure Date: August 12, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in login.asp in Bankoi WebHosting Control Panel 1.20 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field.
0
Attacker Value
Unknown
CVE-2009-2569
Disclosure Date: July 22, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Verlihub Control Panel (VHCP) 1.7e allow remote attackers to inject arbitrary web script or HTML via (1) the nick parameter in a login action to index.php or (2) the URI in a news request to index.html.
0
Attacker Value
Unknown
CVE-2008-6859
Disclosure Date: July 14, 2009 (last updated October 04, 2023)
Xigla Software Absolute Control Panel XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
0
Attacker Value
Unknown
CVE-2009-1504
Disclosure Date: May 01, 2009 (last updated October 04, 2023)
Absolute Form Processor XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting the xlaAFPadmin cookie to "lvl=1&userid=1."
0
Attacker Value
Unknown
CVE-2009-1248
Disclosure Date: April 06, 2009 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Acute Control Panel 1.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the theme_directory parameter to (1) container.php and (2) header.php in themes/.
0