Show filters
140 Total Results
Displaying 131-140 of 140
Sort by:
Attacker Value
Unknown

CVE-2007-0316

Disclosure Date: January 18, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.010 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) xuser_name parameter to shared/code/cp_authorization.php, and the (2) did parameter to public/code/cp_downloads.php, different vectors than CVE-2007-0223.
0
Attacker Value
Unknown

CVE-2007-0223

Disclosure Date: January 13, 2007 (last updated October 04, 2023)
SQL injection vulnerability in shared/code/cp_functions_downloads.php in Nicola Asuni All In One Control Panel (AIOCP) before 1.3.009 allows remote attackers to execute arbitrary SQL commands via the download_category parameter.
0
Attacker Value
Unknown

CVE-2006-5984

Disclosure Date: November 20, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 allow remote authenticated users to inject arbitrary web script or HTML via the (1) txtCompanyName, (2) txtEmail, or (3) txtUserAccNum parameter to (a) users.asp, or the (4) setThemeColour parameter to (b) default.asp in the Reseller and Admin levels; or the (5) setThemeColour parameter to default.asp in the User level. NOTE: the txtDomainName parameter to domains.asp is covered by CVE-2006-1407, which suggests that this vector is fixed in 3.2.10 stable.
0
Attacker Value
Unknown

CVE-2006-3737

Disclosure Date: July 21, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in filemanager/filemanager.php in the control panel in SWsoft Plesk 8.0 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the file parameter.
0
Attacker Value
Unknown

CVE-2006-1407

Disclosure Date: March 28, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) txtDomainName parameter to domains.asp or (2) SearchText or (3) UserLevel parameters to default.asp.
0
Attacker Value
Unknown

CVE-2006-0211

Disclosure Date: January 14, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in forgotPassword.asp in Helm Hosting Control Panel 3.2.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the txtEmailAddress parameter.
0
Attacker Value
Unknown

CVE-2005-4861

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
functions.php in Ragnarok Online Control Panel (ROCP) 4.3.4a allows remote attackers to bypass authentication by requesting account_manage.php with a trailing "/login.php" PHP_SELF value, which is not properly handled by the CHECK_AUTH function.
0
Attacker Value
Unknown

CVE-2004-1498

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary SQL commands via the messageToUserAccNum parameter.
0
Attacker Value
Unknown

CVE-2004-1499

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary web script or HTML via the Subject field.
0
Attacker Value
Unknown

CVE-2000-1023

Disclosure Date: December 11, 2000 (last updated February 22, 2025)
The Alabanza Control Panel does not require passwords to access administrative commands, which allows remote attackers to modify domain name information via the nsManager.cgi CGI program.
0