Show filters
40 Total Results
Displaying 21-30 of 40
Sort by:
Attacker Value
Unknown

CVE-2014-1455

Disclosure Date: April 10, 2014 (last updated October 05, 2023)
SQL injection vulnerability in the password reset functionality in Pearson eSIS Enterprise Student Information System, possibly 3.3.0.13 and earlier, allows remote attackers to execute arbitrary SQL commands via the new password.
0
Attacker Value
Unknown

CVE-2014-1942

Disclosure Date: April 02, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in aal/loginverification.aspx in Pearson eSIS Enterprise Student Information System allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2009-4025

Disclosure Date: November 29, 2009 (last updated October 04, 2023)
Argument injection vulnerability in the traceroute function in Traceroute.php in the Net_Traceroute package before 0.21.2 for PEAR allows remote attackers to execute arbitrary shell commands via the host parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2009-4111

Disclosure Date: November 29, 2009 (last updated October 04, 2023)
Argument injection vulnerability in Mail/sendmail.php in the Mail package 1.1.14, 1.2.0b2, and possibly other versions for PEAR allows remote attackers to read and write arbitrary files via a crafted $recipients parameter, and possibly other parameters, a different vulnerability than CVE-2009-4023.
0
Attacker Value
Unknown

CVE-2009-4024

Disclosure Date: November 29, 2009 (last updated October 04, 2023)
Argument injection vulnerability in the ping function in Ping.php in the Net_Ping package before 2.4.5 for PEAR allows remote attackers to execute arbitrary shell commands via the host parameter. NOTE: this has also been reported as a shell metacharacter problem.
0
Attacker Value
Unknown

CVE-2009-4023

Disclosure Date: November 29, 2009 (last updated October 04, 2023)
Argument injection vulnerability in the sendmail implementation of the Mail::Send method (Mail/sendmail.php) in the Mail package 1.1.14 for PEAR allows remote attackers to read and write arbitrary files via a crafted $from parameter, a different vector than CVE-2009-4111.
0
Attacker Value
Unknown

CVE-2007-5934

Disclosure Date: November 13, 2007 (last updated October 04, 2023)
The LOB functionality in PEAR MDB2 before 2.5.0a1 interprets a request to store a URL string as a request to retrieve and store the contents of the URL, which might allow remote attackers to use MDB2 as an indirect proxy or obtain sensitive information via a URL into a form field in an MDB2 application, as demonstrated by a file:// URL or a URL for an intranet web site.
0
Attacker Value
Unknown

CVE-2007-3628

Disclosure Date: July 09, 2007 (last updated October 04, 2023)
Unspecified vulnerability in the fetch function in MDB2.php in PEAR Structures-DataGrid-DataSource-MDB2 0.1.9 and earlier allows attackers to "manipulate the generated sorting queries."
0
Attacker Value
Unknown

CVE-2007-1044

Disclosure Date: February 21, 2007 (last updated October 04, 2023)
Pearson Education PowerSchool 4.3.6 allows remote attackers to list the contents of the admin folder via a URI composed of the admin/ directory name and an arbitrary filename ending in ".js." NOTE: it was later reported that this issue had been addressed by 5.1.2.
0
Attacker Value
Unknown

CVE-2006-4156

Disclosure Date: August 16, 2006 (last updated November 08, 2023)
PHP remote file inclusion vulnerability in big.php in pearlabs mafia moblog 6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pathtotemplate parameter. NOTE: a third party claims that the researcher is incorrect, because template.php defines pathtotemplate before big.php uses pathtotemplate. CVE has not verified either claim, but during August 2006, the original researcher made several significant errors regarding this bug type
0