Show filters
177 Total Results
Displaying 151-160 of 177
Sort by:
Attacker Value
Unknown

CVE-2010-3374

Disclosure Date: October 04, 2010 (last updated October 04, 2023)
Qt Creator before 2.0.1 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
0
Attacker Value
Unknown

CVE-2010-1217

Disclosure Date: March 30, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in the JE Form Creator (com_jeformcr) component for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via directory traversal sequences in the view parameter to index.php. NOTE: the original researcher states that the affected product is JE Tooltip, not Form Creator; however, the exploit URL suggests that Form Creator is affected.
0
Attacker Value
Unknown

CVE-2010-1114

Disclosure Date: March 25, 2010 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Web Server Creator - Web Portal 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) pg parameter to index.php and the (2) path parameter to news/form.php.
0
Attacker Value
Unknown

CVE-2010-1113

Disclosure Date: March 25, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the forum page in Web Server Creator - Web Portal 0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors to index.php.
0
Attacker Value
Unknown

CVE-2010-1115

Disclosure Date: March 25, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in news/include/customize.php in Web Server Creator - Web Portal 0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the l parameter.
0
Attacker Value
Unknown

CVE-2009-4351

Disclosure Date: December 17, 2009 (last updated October 04, 2023)
SQL injection vulnerability in ADMIN/loginaction.php in WSCreator 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the Email (aka username) parameter.
0
Attacker Value
Unknown

CVE-2009-1566

Disclosure Date: December 03, 2009 (last updated October 04, 2023)
Integer overflow in Roxio Easy Media Creator 9.0.136, and Roxio Creator 2010 before SP1, might allow remote attackers to execute arbitrary code via an image with crafted dimensions.
0
Attacker Value
Unknown

CVE-2009-3330

Disclosure Date: September 23, 2009 (last updated October 04, 2023)
SQL injection vulnerability in index.php in cP Creator 2.7.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the tickets parameter in a support ticket action.
0
Attacker Value
Unknown

CVE-2008-7001

Disclosure Date: August 19, 2009 (last updated October 04, 2023)
Unrestricted file upload vulnerability in the file manager in Creative Mind Creator CMS 5.0 allows remote attackers to execute arbitrary code via unknown vectors.
0
Attacker Value
Unknown

CVE-2008-6545

Disclosure Date: March 30, 2009 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in news/include/createdb.php in Web Server Creator Web Portal 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the langfile parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0