Show filters
141 Total Results
Displaying 131-140 of 141
Sort by:
Attacker Value
Unknown
CVE-2007-0940
Disclosure Date: May 08, 2007 (last updated October 04, 2023)
Unspecified vulnerability in the Cryptographic API Component Object Model Certificates ActiveX control (CAPICOM.dll) in Microsoft CAPICOM and BizTalk Server 2004 SP1 and SP2 allows remote attackers to execute arbitrary code via unspecified vectors, aka the "CAPICOM.Certificates Vulnerability."
0
Attacker Value
Unknown
CVE-2006-6588
Disclosure Date: December 15, 2006 (last updated October 04, 2023)
The forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) trusts the (1) dataResourceTypeId, (2) contentTypeId, and certain other hidden form fields, which allows remote attackers to create unauthorized types of content, modify content, or have other unknown impact.
0
Attacker Value
Unknown
CVE-2006-6589
Disclosure Date: December 15, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in ecommerce/control/keywordsearch in the Apache Open For Business Project (OFBiz) and Opentaps 0.9.3 allows remote attackers to inject arbitrary web script or HTML via the SEARCH_STRING parameter, a different issue than CVE-2006-6587. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2006-6587
Disclosure Date: December 15, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) allows remote attackers to inject arbitrary web script or HTML by posting a message.
0
Attacker Value
Unknown
CVE-2006-4883
Disclosure Date: September 19, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot BizDirectory allow remote attackers to inject arbitrary web script or HTML via (1) the stylesheet parameter in Feed.php or (2) the message parameter in status.php.
0
Attacker Value
Unknown
CVE-2006-3327
Disclosure Date: June 30, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Custom dating biz dating script 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) sn20_special_cases parameter ("Special Cases" field) in profile/mini.php, (2) tyxx01_album_name parameter ("Album Name" field) in profile/photo_create.php, and the (3) u parameter in admin/user_view.php.
0
Attacker Value
Unknown
CVE-2005-2135
Disclosure Date: July 05, 2005 (last updated February 22, 2025)
SQL injection vulnerability in verify.asp in EtoShop Dynamic Biz Website Builder (QuickWeb) 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) T1 or (2) T2 parameters.
0
Attacker Value
Unknown
CVE-2005-0493
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
CRLF injection vulnerability in bizmail.cgi in Biz Mail Form before 2.2 allows remote attackers to bypass the email check and send spam e-mail via CRLF sequences and forged mail headers in the email parameter.
0
Attacker Value
Unknown
CVE-2003-0117
Disclosure Date: May 12, 2003 (last updated February 22, 2025)
Buffer overflow in the HTTP receiver function (BizTalkHTTPReceive.dll ISAPI) of Microsoft BizTalk Server 2002 allows attackers to execute arbitrary code via a certain request to the HTTP receiver.
0
Attacker Value
Unknown
CVE-2003-0118
Disclosure Date: May 12, 2003 (last updated February 22, 2025)
SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attackers to execute operating system commands via a request to (1) rawdocdata.asp or (2) RawCustomSearchField.asp containing an embedded SQL statement.
0