Show filters
37 Total Results
Displaying 21-30 of 37
Sort by:
Attacker Value
Unknown

CVE-2006-5122

Disclosure Date: October 03, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Mercury SiteScope 8.2 (8.1.2.0) allow remote authenticated users to inject arbitrary web script or HTML via (1) "any field create name field" except "create new group name" or (2) any description field.
0
Attacker Value
Unknown

CVE-2006-3669

Disclosure Date: July 18, 2006 (last updated October 04, 2023)
Mercury Messenger, possibly 1.7.1.1 and other versions, when running on a multi-user Mac OS X platform, stores chat logs with world-readable permissions within the /Users directory, which allows local users to read the chat logs from other users.
0
Attacker Value
Unknown

CVE-2005-4411

Disclosure Date: December 20, 2005 (last updated February 22, 2025)
Buffer overflow in Mercury Mail Transport System 4.01b allows remote attackers to execute arbitrary code via a long request to TCP port 105.
0
Attacker Value
Unknown

CVE-2005-4406

Disclosure Date: December 20, 2005 (last updated February 22, 2025)
SQL injection vulnerability in index.cfm in Mercury CMS 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter.
0
Attacker Value
Unknown

CVE-2005-4407

Disclosure Date: December 20, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in index.cfm in Mercury CMS 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) content and (2) criteria parameters.
0
Attacker Value
Unknown

CVE-2005-2028

Disclosure Date: June 21, 2005 (last updated February 22, 2025)
SQL injection vulnerability in index.php for MercuryBoard 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.
0
Attacker Value
Unknown

CVE-2005-0460

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
index.php in MercuryBoard 1.0.x and 1.1.x allows remote attackers to obtain sensitive information by setting the debug parameter.
0
Attacker Value
Unknown

CVE-2005-0662

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in index.php for MercuryBoard 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the Avatar field.
0
Attacker Value
Unknown

CVE-2005-0663

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
SQL injection vulnerability in index.php for MercuryBoard 1.1.2 allows remote attackers to inject arbitrary SQL commands via the f parameter.
0
Attacker Value
Unknown

CVE-2005-0414

Disclosure Date: April 27, 2005 (last updated February 22, 2025)
SQL injection vulnerability in post.php for MercuryBoard 1.1.1 allows remote attackers to execute arbitrary SQL commands via a reply post action for index.php with (1) the t parameter or (2) the qu parameter.
0