Show filters
205 Total Results
Displaying 191-200 of 205
Sort by:
Attacker Value
Unknown

CVE-2016-2381

Disclosure Date: April 08, 2016 (last updated November 25, 2024)
Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.
Attacker Value
Unknown

CVE-2015-3319

Disclosure Date: April 16, 2015 (last updated October 05, 2023)
Hotspot Express hotEx Billing Manager 73 does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
0
Attacker Value
Unknown

CVE-2015-2781

Disclosure Date: April 14, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in cgi-bin/hotspotlogin.cgi in Hotspot Express hotEx Billing Manager 73 allows remote attackers to inject arbitrary web script or HTML via the reply parameter.
0
Attacker Value
Unknown

CVE-2010-5292

Disclosure Date: January 10, 2014 (last updated October 05, 2023)
Amberdms Billing System (ABS) before 1.4.1, when a multi-instance installation is configured, might allow local users to obtain sensitive information by reading the cache in between runs of the include/cron/services_usage.php cron job.
0
Attacker Value
Unknown

CVE-2010-5291

Disclosure Date: January 10, 2014 (last updated October 05, 2023)
Amberdms Billing System (ABS) before 1.4.1 does not properly implement blacklisting after detection of invalid login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach.
0
Attacker Value
Unknown

CVE-2013-2251

Disclosure Date: July 20, 2013 (last updated July 17, 2024)
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.
Attacker Value
Unknown

CVE-2011-0510

Disclosure Date: January 20, 2011 (last updated October 04, 2023)
SQL injection vulnerability in cart.php in Advanced Webhost Billing System (AWBS) 2.9.2 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the oid parameter in an add_other action.
0
Attacker Value
Unknown

CVE-2008-5632

Disclosure Date: December 17, 2008 (last updated October 04, 2023)
SQL injection vulnerability in Account.asp in Active Time Billing 3.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, possibly related to start.asp. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-2903

Disclosure Date: June 30, 2008 (last updated October 04, 2023)
SQL injection vulnerability in news.php in Advanced Webhost Billing System (AWBS) 2.3.3 through 2.7.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the viewnews parameter.
0
Attacker Value
Unknown

CVE-2008-0693

Disclosure Date: February 12, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in PQCore.exe in Print Manager Plus 2008 Client Billing and Authentication 7.0.127.16 allows remote attackers to cause a denial of service (service outage) via a series of long packets to TCP port 48101.
0