Show filters
251 Total Results
Displaying 201-210 of 251
Sort by:
Attacker Value
Unknown

CVE-2009-2120

Disclosure Date: June 18, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in TekBase All-in-One 3.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) ids parameter to admin.php, the (2) y parameter to members.php, and other unspecified vectors. NOTE: vector 1 requires administrative access.
0
Attacker Value
Unknown

CVE-2009-2036

Disclosure Date: June 12, 2009 (last updated October 04, 2023)
SQL injection vulnerability in index.php in Open Biller 0.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.
0
Attacker Value
Unknown

CVE-2009-1607

Disclosure Date: May 11, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the administrator panel in phpForm.net LinkBase 2.0 allows remote attackers to inject arbitrary web script or HTML via the username in a registration, which is not properly handled when the administrator accesses the Users menu.
0
Attacker Value
Unknown

CVE-2008-6513

Disclosure Date: March 24, 2009 (last updated October 04, 2023)
Unrestricted file upload vulnerability in saa.php in Andy's PHP Knowledgebase (aphpkb) 0.92.9 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a link that is listed by authors.php.
0
Attacker Value
Unknown

CVE-2008-4346

Disclosure Date: September 30, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in TalkBack 2.3.6 and 2.3.6.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter to comments.php, a different vector than CVE-2008-3371.
0
Attacker Value
Unknown

CVE-2008-4175

Disclosure Date: September 23, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Link Bid Script 1.5 allow remote attackers to execute arbitrary SQL commands via the (1) ucat parameter to upgrade.php and the (2) id parameter to linkadmin/edit.php.
0
Attacker Value
Unknown

CVE-2008-4115

Disclosure Date: September 16, 2008 (last updated October 04, 2023)
TalkBack 2.3.6 allows remote attackers to obtain configuration information via a direct request to install/info.php, which calls the phpinfo function.
0
Attacker Value
Unknown

CVE-2008-3421

Disclosure Date: July 31, 2008 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in Blackboard Academic Suite 8.0.260.7 allow remote attackers to hijack the authentication of student users for requests that change configuration and enrollments via unspecified input to (1) update_module.jsp, (2) enroll_course.pl, and (3) unenroll.jsp.
0
Attacker Value
Unknown

CVE-2008-3371

Disclosure Date: July 30, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in install/help.php in TalkBack 2.3.5, and other versions before 2.3.6.2, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the language parameter.
0
Attacker Value
Unknown

CVE-2008-3246

Disclosure Date: July 21, 2008 (last updated October 04, 2023)
Unspecified vulnerability in the PDF distiller component in the BlackBerry Attachment Service in BlackBerry Unite! 1.0 SP1 (1.0.1) before bundle 36 and BlackBerry Enterprise Server 4.1 SP3 (4.1.3) through 4.1 SP5 (4.1.5) allows user-assisted remote attackers to execute arbitrary code via a crafted PDF file attachment.
0