Show filters
194 Total Results
Displaying 181-190 of 194
Sort by:
Attacker Value
Unknown
CVE-2009-0125
Disclosure Date: January 15, 2009 (last updated November 08, 2023)
NOTE: this issue has been disputed by the upstream vendor. nasl/nasl_crypto2.c in the Nessus Attack Scripting Language library (aka libnasl) 2.2.11 does not properly check the return value from the OpenSSL DSA_do_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. NOTE: the upstream vendor has disputed this issue, stating "while we do misuse this function (this is a bug), it has absolutely no security ramification.
0
Attacker Value
Unknown
CVE-2008-5207
Disclosure Date: November 21, 2008 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in Jonascms 1.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the taal parameter to (1) backup.php and (2) gb_voegtoe.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2008-1046
Disclosure Date: February 27, 2008 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in footer.php in Quinsonnas Mail Checker 1.55 allows remote attackers to execute arbitrary PHP code via a URL in the op[footer_body] parameter.
0
Attacker Value
Unknown
CVE-2008-0804
Disclosure Date: February 19, 2008 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in usrgetform.html in Thecus N5200Pro NAS Server allows remote attackers to execute arbitrary PHP code via a URL in the name parameter.
0
Attacker Value
Unknown
CVE-2007-6340
Disclosure Date: February 05, 2008 (last updated October 04, 2023)
Geert Moernaut LSrunasE 1.0 and Supercrypt 1.0 use the RC4 stream cipher without constructing a unique initialization vector (IV), which makes it easier for local users to obtain cleartext passwords.
0
Attacker Value
Unknown
CVE-2008-0581
Disclosure Date: February 05, 2008 (last updated October 04, 2023)
Geert Moernaut LSrunasE allows local users to gain privileges by obtaining the encrypted password from a batch file, and constructing a modified batch file that specifies this password in the /password switch and specifies an arbitrary program in the /command switch.
0
Attacker Value
Unknown
CVE-2008-0580
Disclosure Date: February 05, 2008 (last updated October 04, 2023)
Geert Moernaut LSrunasE and Supercrypt use an encryption key composed of an SHA1 hash of a fixed string embedded in the executable file, which makes it easier for local users to obtain this key without reverse engineering.
0
Attacker Value
Unknown
CVE-2007-4361
Disclosure Date: August 15, 2007 (last updated October 04, 2023)
NETGEAR (formerly Infrant) ReadyNAS RAIDiator before 4.00b2-p2-T1 beta creates a default SSH root password derived from the hardware serial number, which makes it easier for remote attackers to guess the password and obtain login access.
0
Attacker Value
Unknown
CVE-2007-2335
Disclosure Date: April 27, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the RSS feed reader functionality in Lunascape 4.1.3 build2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2006-5760
Disclosure Date: November 06, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in phpDynaSite 3.2.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the racine parameter to (1) function_log.php, (2) function_balise_url.php, or (3) connection.php.
0