Show filters
200 Total Results
Displaying 171-180 of 200
Sort by:
Attacker Value
Unknown

CVE-2007-4624

Disclosure Date: August 31, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in pframe.php in AbleDesign Dynamic Picture Frame 1.00 allows remote attackers to inject arbitrary web script or HTML via the img_url parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2007-1635

Disclosure Date: March 23, 2007 (last updated October 04, 2023)
Static code injection vulnerability in admin/settings.php in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote authenticated users to inject arbitrary PHP code via the xtop parameter in a "ConfigSave" op to admin.php, which can later be accessed via a "Configure" op to admin.php.
0
Attacker Value
Unknown

CVE-2007-1634

Disclosure Date: March 23, 2007 (last updated October 04, 2023)
Variable extraction vulnerability in grab_globals.php in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote attackers to conduct SQL injection attacks via the _FILES[DB][tmp_name] parameter to print.php, which overwrites the $DB variable with dynamic variable evaluation.
0
Attacker Value
Unknown

CVE-2007-1419

Disclosure Date: March 12, 2007 (last updated October 04, 2023)
The Java Management Extensions Remote API Remote Method Invocation over Internet Inter-ORB Protocol (JMX RMI-IIOP) API in Java Dynamic Management Kit 5.1 before 20070309 does not properly enforce the java.policy, which allows local users to obtain certain MBeans data access by operating a server application accessed by a privileged remote authenticated user.
0
Attacker Value
Unknown

CVE-2006-5664

Disclosure Date: November 03, 2006 (last updated October 04, 2023)
The installation script in IBM Informix Dynamic Server 10.00, Informix Client Software Development Kit (CSDK) 2.90, and Informix I-Connect 2.90 allows local users to "compromise security" via a symlink attack on temporary files.
0
Attacker Value
Unknown

CVE-2006-5663

Disclosure Date: November 03, 2006 (last updated October 04, 2023)
IBM Informix Dynamic Server 10.00, Informix Client Software Development Kit (CSDK) 2.90, and Informix I-Connect 2.90 use insecure permissions for installation scripts, which allows local users to gain privileges by modifying the scripts.
0
Attacker Value
Unknown

CVE-2006-5163

Disclosure Date: October 05, 2006 (last updated October 04, 2023)
IBM Informix Dynamic Server 10.UC3RC1 Trial for Linux and possibly other versions creates /tmp/installserver.txt with insecure permissions, which allows local users to append data to arbitrary files via a symlink attack.
0
Attacker Value
Unknown

CVE-2006-3859

Disclosure Date: August 17, 2006 (last updated October 04, 2023)
IBM Informix Dynamic Server (IDS) allows remote authenticated users to create and overwrite arbitrary files via the (1) LOTOFILE and (2) trl_tracefile_set functions, and the (3) "SET DEBUG FILE" commands.
0
Attacker Value
Unknown

CVE-2006-3854

Disclosure Date: August 17, 2006 (last updated October 04, 2023)
Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.TC7, 9.40.TC8, 10.00.TC4, and 10.00.TC5, when running on Windows, allows remote attackers to execute arbitrary code via a long username, which causes an overflow in vsprintf when displaying in the resulting error message. NOTE: this issue is due to an incomplete fix for CVE-2006-3853.
0
Attacker Value
Unknown

CVE-2006-3860

Disclosure Date: August 17, 2006 (last updated October 04, 2023)
IBM Informix Dynamic Server (IDS) before 9.40.xC7 and 10.00 before 10.00.xC3 allows allows remote authenticated users to execute arbitrary commands via the (1) "SET DEBUG FILE" SQL command, and the (2) start_onpload and (3) dbexp functions.
0