Show filters
48 Total Results
Displaying 21-30 of 48
Sort by:
Attacker Value
Unknown
CVE-2016-1542
Disclosure Date: June 13, 2016 (last updated November 25, 2024)
The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and enumerate users by sending an action packet to xmlrpc after an authorization failure.
0
Attacker Value
Unknown
CVE-2016-1543
Disclosure Date: June 13, 2016 (last updated November 25, 2024)
The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and reset arbitrary user passwords by sending an action packet to xmlrpc after an authorization failure.
0
Attacker Value
Unknown
CVE-2012-4489
Disclosure Date: October 31, 2012 (last updated October 05, 2023)
Open redirect vulnerability in the securelogin_secure_redirect function in the Secure Login module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter.
0
Attacker Value
Unknown
CVE-2011-1389
Disclosure Date: January 19, 2012 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in the vendor daemon in Rational Common Licensing in Telelogic License Server 2.0, Rational License Server 7.x, and ibmratl in IBM Rational License Key Server (RLKS) 8.0 through 8.1.2 allow remote attackers to execute arbitrary code via vectors related to save, rename, and load operations on log files. NOTE: this might overlap CVE-2011-4135.
0
Attacker Value
Unknown
CVE-2010-4980
Disclosure Date: November 01, 2011 (last updated October 04, 2023)
SQL injection vulnerability in packagedetails.php in iScripts ReserveLogic 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.
0
Attacker Value
Unknown
CVE-2009-4733
Disclosure Date: March 18, 2010 (last updated October 04, 2023)
SQL injection vulnerability in checkuser.php in SimpleLoginSys 0.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2008-7206
Disclosure Date: September 11, 2009 (last updated October 04, 2023)
Unspecified vulnerability in Electronic Logbook (ELOG) before 2.7.2 has unknown impact and attack vectors when the "logbook contains HTML code," probably cross-site scripting (XSS).
0
Attacker Value
Unknown
CVE-2008-7004
Disclosure Date: August 19, 2009 (last updated October 04, 2023)
Buffer overflow in Electronic Logbook (ELOG) before 2.7.1 has unknown impact and attack vectors, possibly related to elog.c.
0
Attacker Value
Unknown
CVE-2008-0444
Disclosure Date: January 25, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) before 2.7.0 allows remote attackers to inject arbitrary web script or HTML via subtext parameter to unspecified components.
0
Attacker Value
Unknown
CVE-2008-0445
Disclosure Date: January 25, 2008 (last updated October 04, 2023)
The replace_inline_img function in elogd in Electronic Logbook (ELOG) before 2.7.1 allows remote attackers to cause a denial of service (infinite loop) via crafted logbook entries. NOTE: some of these details are obtained from third party information.
0