Show filters
28 Total Results
Displaying 21-28 of 28
Sort by:
Attacker Value
Unknown
CVE-2014-10070
Disclosure Date: February 27, 2018 (last updated November 26, 2024)
zsh before 5.0.7 allows evaluation of the initial values of integer variables imported from the environment (instead of treating them as literal numbers). That could allow local privilege escalation, under some specific and atypical conditions where zsh is being invoked in privilege-elevation contexts when the environment has not been properly sanitized, such as when zsh is invoked by sudo on systems where "env_reset" has been disabled.
0
Attacker Value
Unknown
CVE-2007-6209
Disclosure Date: December 04, 2007 (last updated October 04, 2023)
Util/difflog.pl in zsh 4.3.4 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
0
Attacker Value
Unknown
CVE-2007-1905
Disclosure Date: April 10, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in auth.php in Pineapple Technologies QuizShock 1.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via encoded special characters in the forward_to parameter, as demonstrated using "<"<".
0
Attacker Value
Unknown
CVE-2005-4571
Disclosure Date: December 29, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in myEZshop Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the Keyword parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2005-4572
Disclosure Date: December 29, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in myEZshop Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) GroupsId and (2) ItemsId parameters in admin.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2000-1092
Disclosure Date: January 09, 2001 (last updated February 22, 2025)
loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data directory by inserting a "/" in front of the target filename in the "file" parameter.
0
Attacker Value
Unknown
CVE-2000-0187
Disclosure Date: February 27, 2000 (last updated February 22, 2025)
EZShopper 3.0 loadpage.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters.
0
Attacker Value
Unknown
CVE-2000-0188
Disclosure Date: February 27, 2000 (last updated February 22, 2025)
EZShopper 3.0 search.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters.
0