Show filters
48 Total Results
Displaying 21-30 of 48
Sort by:
Attacker Value
Unknown

CVE-2016-1542

Disclosure Date: June 13, 2016 (last updated November 25, 2024)
The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and enumerate users by sending an action packet to xmlrpc after an authorization failure.
0
Attacker Value
Unknown

CVE-2016-1543

Disclosure Date: June 13, 2016 (last updated November 25, 2024)
The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and reset arbitrary user passwords by sending an action packet to xmlrpc after an authorization failure.
0
Attacker Value
Unknown

CVE-2012-4489

Disclosure Date: October 31, 2012 (last updated October 05, 2023)
Open redirect vulnerability in the securelogin_secure_redirect function in the Secure Login module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter.
0
Attacker Value
Unknown

CVE-2011-1389

Disclosure Date: January 19, 2012 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in the vendor daemon in Rational Common Licensing in Telelogic License Server 2.0, Rational License Server 7.x, and ibmratl in IBM Rational License Key Server (RLKS) 8.0 through 8.1.2 allow remote attackers to execute arbitrary code via vectors related to save, rename, and load operations on log files. NOTE: this might overlap CVE-2011-4135.
0
Attacker Value
Unknown

CVE-2010-4980

Disclosure Date: November 01, 2011 (last updated October 04, 2023)
SQL injection vulnerability in packagedetails.php in iScripts ReserveLogic 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.
0
Attacker Value
Unknown

CVE-2009-4733

Disclosure Date: March 18, 2010 (last updated October 04, 2023)
SQL injection vulnerability in checkuser.php in SimpleLoginSys 0.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-7206

Disclosure Date: September 11, 2009 (last updated October 04, 2023)
Unspecified vulnerability in Electronic Logbook (ELOG) before 2.7.2 has unknown impact and attack vectors when the "logbook contains HTML code," probably cross-site scripting (XSS).
0
Attacker Value
Unknown

CVE-2008-7004

Disclosure Date: August 19, 2009 (last updated October 04, 2023)
Buffer overflow in Electronic Logbook (ELOG) before 2.7.1 has unknown impact and attack vectors, possibly related to elog.c.
0
Attacker Value
Unknown

CVE-2008-0444

Disclosure Date: January 25, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) before 2.7.0 allows remote attackers to inject arbitrary web script or HTML via subtext parameter to unspecified components.
0
Attacker Value
Unknown

CVE-2008-0445

Disclosure Date: January 25, 2008 (last updated October 04, 2023)
The replace_inline_img function in elogd in Electronic Logbook (ELOG) before 2.7.1 allows remote attackers to cause a denial of service (infinite loop) via crafted logbook entries. NOTE: some of these details are obtained from third party information.
0