Show filters
53 Total Results
Displaying 21-30 of 53
Sort by:
Attacker Value
Unknown
CVE-2012-4469
Disclosure Date: November 30, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Hashcash module 6.x-2.x before 6.x-2.6 and 7.x-2.x before 7.x-2.2 for Drupal, when "Log failed hashcash" is enabled, allows remote attackers to inject arbitrary web script or HTML via an invalid token, which is not properly handled when administrators use the Database logging module.
0
Attacker Value
Unknown
CVE-2012-4023
Disclosure Date: November 08, 2012 (last updated October 05, 2023)
CRLF injection vulnerability in Pebble before 2.6.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-4022
Disclosure Date: November 08, 2012 (last updated October 05, 2023)
Pebble before 2.6.4 allows remote attackers to trigger loss of blog-entry viewability via a crafted comment.
0
Attacker Value
Unknown
CVE-2012-5170
Disclosure Date: November 04, 2012 (last updated October 05, 2023)
Open redirect vulnerability in Pebble before 2.6.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
0
Attacker Value
Unknown
CVE-2010-4904
Disclosure Date: October 08, 2011 (last updated October 04, 2023)
SQL injection vulnerability in the Aardvertiser (com_aardvertiser) component 2.1 and 2.1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_name parameter in a view action to index.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2011-0432
Disclosure Date: March 14, 2011 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in the get_userinfo method in the MySQLAuthHandler class in DAVServer/mysqlauth.py in PyWebDAV before 0.9.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) user or (2) pw argument. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2010-2945
Disclosure Date: August 30, 2010 (last updated October 04, 2023)
The default configuration of SLiM before 1.3.2 places ./ (dot slash) at the beginning of the default_path option, which might allow local users to gain privileges via a Trojan horse program in the current working directory, related to slim.conf and cfg.cpp.
0
Attacker Value
Unknown
CVE-2010-3028
Disclosure Date: August 16, 2010 (last updated October 04, 2023)
The Aardvertiser component before 2.2.1 for Joomla! uses insecure permissions (777) in unspecified folders, which allows local users to modify, create, or delete certain files.
0
Attacker Value
Unknown
CVE-2010-1013
Disclosure Date: March 19, 2010 (last updated October 04, 2023)
SQL injection vulnerability in the Diocese of Portsmouth Database (pd_diocesedatabase) extension before 0.7.13 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2010-0985
Disclosure Date: March 16, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in the Abbreviations Manager (com_abbrev) component 1.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.
0