Show filters
164 Total Results
Displaying 151-160 of 164
Sort by:
Attacker Value
Unknown
CVE-2010-2253
Disclosure Date: July 06, 2010 (last updated October 04, 2023)
lwp-download in libwww-perl before 5.835 does not reject downloads to filenames that begin with a . (dot) character, which allows remote servers to create or overwrite files via (1) a 3xx redirect to a URL with a crafted filename or (2) a Content-Disposition header that suggests a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.
0
Attacker Value
Unknown
CVE-2010-0328
Disclosure Date: January 15, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Unit Converter (cs2_unitconv) extension 1.0.4 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2009-3818
Disclosure Date: October 28, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the session handling feature in freeCap CAPTCHA (sr_freecap) extension 1.2.0 and earlier for TYPO3 has unknown impact and attack vectors.
0
Attacker Value
Unknown
CVE-2009-1264
Disclosure Date: April 07, 2009 (last updated October 04, 2023)
Frontend User Registration (sr_feuser_register) extension 2.5.20 and earlier for TYPO3 does not properly verify access rights, which allows remote authenticated users to obtain sensitive information such as passwords via unknown attack vectors.
0
Attacker Value
Unknown
CVE-2006-7236
Disclosure Date: January 02, 2009 (last updated October 04, 2023)
The default configuration of xterm on Debian GNU/Linux sid and possibly Ubuntu enables the allowWindowOps resource, which allows user-assisted attackers to execute arbitrary code or have unspecified other impact via escape sequences.
0
Attacker Value
Unknown
CVE-2008-2383
Disclosure Date: January 02, 2009 (last updated October 04, 2023)
CRLF injection vulnerability in xterm allows user-assisted attackers to execute arbitrary commands via LF (aka \n) characters surrounding a command name within a Device Control Request Status String (DECRQSS) escape sequence in a text file, a related issue to CVE-2003-0063 and CVE-2003-0071.
0
Attacker Value
Unknown
CVE-2007-4756
Disclosure Date: September 08, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in the FTP client in Total Commander before 7.02 allows remote FTP servers to create or overwrite arbitrary files via "..\" (dot dot backslash) sequences in a filename. NOTE: the "..\" are not displayed when the user lists files. NOTE: this can be leveraged for code execution by writing to a Startup folder.
0
Attacker Value
Unknown
CVE-2007-4463
Disclosure Date: August 21, 2007 (last updated October 04, 2023)
The Fileinfo 2.0.9 plugin for Total Commander allows user-assisted remote attackers to cause a denial of service (unhandled exception) via an invalid RVA address function pointer in (1) an IMAGE_THUNK_DATA structure, involving the (a) OriginalFirstThunk and (b) FirstThunk IMAGE_IMPORT_DESCRIPTOR fields, or (2) the AddressOfNames IMAGE_EXPORT_DIRECTORY field in a PE file.
0
Attacker Value
Unknown
CVE-2007-4464
Disclosure Date: August 21, 2007 (last updated October 04, 2023)
CRLF injection vulnerability in the Fileinfo 2.0.9 plugin for Total Commander allows user-assisted remote attackers to spoof the information in the Image File Header tab via strings with CRLF sequences in the IMAGE_EXPORT_DIRECTORY array in a PE file, which could complicate forensics investigations.
0
Attacker Value
Unknown
CVE-2006-5517
Disclosure Date: October 26, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Rhode Island Open Meetings Filing Application (OMFA) allow remote attackers to execute arbitrary PHP code via a URL in the PROJECT_ROOT parameter to (1) editmeetings/session.php, (2) email/session.php, (3) entityproperties/session.php, or (4) inc/mail.php.
0