Show filters
224 Total Results
Displaying 151-160 of 224
Sort by:
Attacker Value
Unknown

CVE-2015-2965

Disclosure Date: June 28, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in osCommerce Japanese 2.2ms1j-R8 and earlier allows remote authenticated administrators to read arbitrary files via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-0747

Disclosure Date: May 30, 2015 (last updated October 05, 2023)
Cisco Conductor for Videoscape 3.0 and Cisco Headend System Release allow remote attackers to inject arbitrary cookies via a crafted HTTP request, aka Bug ID CSCuh25408.
0
Attacker Value
Unknown

CVE-2012-1665

Disclosure Date: May 20, 2015 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in the admin panel in osCMax before 2.5.1 allow (1) remote attackers to execute arbitrary SQL commands via the username parameter in a process action to admin/login.php or (2) remote administrators to execute arbitrary SQL commands via the status parameter to admin/stats_monthly_sales.php or (3) country parameter in a process action to admin/create_account_process.php.
0
Attacker Value
Unknown

CVE-2012-6691

Disclosure Date: May 20, 2015 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in the admin panel in osCMax before 2.5.1 allow remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the (1) status parameter to admin/stats_monthly_sales.php or (2) country parameter in a process action to admin/create_account_process.php.
0
Attacker Value
Unknown

CVE-2012-1664

Disclosure Date: May 20, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the admin panel in osCMax before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter in a process action to admin/login.php; (2) pageTitle, (3) current_product_id, or (4) cPath parameter to admin/new_attributes_include.php; (5) sb_id, (6) sb_key, (7) gc_id, (8) gc_key, or (9) path parameter to admin/htaccess.php; (10) title parameter to admin/information_form.php; (11) search parameter to admin/xsell.php; (12) gross or (13) max parameter to admin/stats_products_purchased.php; (14) status parameter to admin/stats_monthly_sales.php; (15) sorted parameter to admin/stats_customers.php; (16) information_id parameter to /admin/information_manager.php; or (17) zID parameter to /admin/geo_zones.php.
0
Attacker Value
Unknown

CVE-2015-0671

Disclosure Date: March 20, 2015 (last updated October 05, 2023)
The DNS implementation in Cisco Videoscape Distribution Suite for Internet Streaming (VDS-IS) 3.2(1) allows remote attackers to cause a denial of service (CPU consumption and network-resource consumption) via crafted packets, aka Bug ID CSCun15911.
0
Attacker Value
Unknown

CVE-2015-0778

Disclosure Date: March 16, 2015 (last updated October 05, 2023)
osc before 0.151.0 allows remote attackers to execute arbitrary commands via shell metacharacters in a _service file.
0
Attacker Value
Unknown

CVE-2014-8085

Disclosure Date: January 05, 2015 (last updated October 05, 2023)
Unrestricted file upload vulnerability in the CWebContact::doModel method in oc-includes/osclass/controller/contact.php in OSClass before 3.4.3 allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in an unspecified directory.
0
Attacker Value
Unknown

CVE-2014-8084

Disclosure Date: January 05, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in oc-includes/osclass/controller/ajax.php in OSClass before 3.4.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ajaxfile parameter in a custom action.
0
Attacker Value
Unknown

CVE-2014-8083

Disclosure Date: January 05, 2015 (last updated October 05, 2023)
SQL injection vulnerability in the Search::setJsonAlert method in OSClass before 3.4.3 allows remote attackers to execute arbitrary SQL commands via the alert parameter in a search alert subscription action.
0