Show filters
145 Total Results
Displaying 131-140 of 145
Sort by:
Attacker Value
Unknown
CVE-2005-3823
Disclosure Date: November 26, 2005 (last updated February 22, 2025)
The Users module in vTiger CRM 4.2 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary file in the templatename parameter, which is passed to the eval function.
0
Attacker Value
Unknown
CVE-2005-3822
Disclosure Date: November 26, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username in the login form or (2) record parameter, as demonstrated in the EditView action for the Contacts module.
0
Attacker Value
Unknown
CVE-2005-3819
Disclosure Date: November 26, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary SQL commands and bypass authentication via the (1) user_name and (2) date parameter in the HelpDesk module.
0
Attacker Value
Unknown
CVE-2005-3818
Disclosure Date: November 26, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) various input fields, including the contact, lead, and first or last name fields, (2) the record parameter in a DetailView action in the Leads module for index.php, (3) the $_SERVER['PHP_SELF'] variable, which is used in multiple locations such as index.php, and (4) aggregated RSS feeds in the RSS aggregation module.
0
Attacker Value
Unknown
CVE-2005-0978
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Directory traversal vulnerability in the Object Push service in IVT BlueSoleil 1.4 allows remote attackers to upload arbitrary files via a .. (dot dot) in a PUSH command.
0
Attacker Value
Unknown
CVE-2003-0022
Disclosure Date: March 03, 2003 (last updated February 22, 2025)
The "screen dump" feature in rxvt 2.7.8 allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to a user's terminal, e.g. when the user views a file containing the malicious sequence.
0
Attacker Value
Unknown
CVE-2003-0023
Disclosure Date: March 03, 2003 (last updated February 22, 2025)
The menuBar feature in rxvt 2.7.8 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu.
0
Attacker Value
Unknown
CVE-2003-0066
Disclosure Date: March 03, 2003 (last updated February 22, 2025)
The rxvt terminal emulator 2.7.8 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.
0
Attacker Value
Unknown
CVE-2002-1697
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Electronic Code Book (ECB) mode in VTun 2.0 through 2.5 uses a weak encryption algorithm that produces the same ciphertext from the same plaintext blocks, which could allow remote attackers to gain sensitive information.
0
Attacker Value
Unknown
CVE-2001-1294
Disclosure Date: August 22, 2001 (last updated February 22, 2025)
Buffer overflow in A-V Tronics Inetserv 3.2.1 and earlier allows remote attackers to cause a denial of service (crash) in the Webmail interface via a long username and password.
0