Show filters
219 Total Results
Displaying 201-210 of 219
Sort by:
Attacker Value
Unknown
CVE-2009-3994
Disclosure Date: December 08, 2009 (last updated October 04, 2023)
Stack-based buffer overflow in the GetUID function in src-IL/src/il_dicom.c in DevIL 1.7.8 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted DICOM file.
0
Attacker Value
Unknown
CVE-2009-3824
Disclosure Date: October 28, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in include/processor.php in Greenwood PHP Content Manager 0.3.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the content_path parameter.
0
Attacker Value
Unknown
CVE-2009-3353
Disclosure Date: September 24, 2009 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in the Node2Node module for Drupal have unknown impact and attack vectors.
0
Attacker Value
Unknown
CVE-2008-6739
Disclosure Date: April 21, 2009 (last updated October 04, 2023)
Todd Woolums ASP Download management script 1.03 does not require authentication for setupdownload.asp, which allows remote attackers to gain administrator privileges via a direct request.
0
Attacker Value
Unknown
CVE-2008-5274
Disclosure Date: November 28, 2008 (last updated October 04, 2023)
Todd Woolums ASP News Management 2.2 allows remote attackers to obtain news items via a direct request to (1) rss.asp, (2) viewheadings.asp, or (3) viewnews.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2008-5273
Disclosure Date: November 28, 2008 (last updated October 04, 2023)
SQL injection vulnerability in viewnews.asp in Todd Woolums ASP News Management 2.2 allows remote attackers to execute arbitrary SQL commands via the newsID parameter.
0
Attacker Value
Unknown
CVE-2008-4976
Disclosure Date: November 06, 2008 (last updated October 04, 2023)
ogle 0.9.2 and ogle-mmx 0.9.2 allow local users to overwrite arbitrary files via a symlink attack on (a) /tmp/ogle_audio.#####, (b) /tmp/ogle_cli.#####, (c) /tmp/ogle_ctrl.#####, (d) /tmp/ogle_gui.#####, (e) /tmp/ogle_mpeg_ps.#####, (f) /tmp/ogle_mpeg_vs.#####, (g) /tmp/ogle_nav.#####, and (h) /tmp/ogle_vout.#####, temporary files, related to the (1) ogle_audio_debug, (2) ogle_cli_debug, (3) ogle_ctrl_debug, (4) ogle_gui_debug, (5) ogle_mpeg_ps_debug, (6) ogle_mpeg_vs_debug, (7) ogle_nav_debug, and (8) ogle_vout_debug scripts.
0
Attacker Value
Unknown
CVE-2008-4511
Disclosure Date: October 09, 2008 (last updated October 04, 2023)
Todd Woolums ASP News Management, possibly 2.21, stores db/news.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request.
0
Attacker Value
Unknown
CVE-2008-4439
Disclosure Date: October 03, 2008 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in admin/bin/patch.php in MartinWood Datafeed Studio before 1.6.3 allows remote attackers to execute arbitrary PHP code via a URL in the INSTALL_FOLDER parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2008-1106
Disclosure Date: June 09, 2008 (last updated October 04, 2023)
The management interface in Akamai Client (formerly Red Swoosh) 3322 and earlier allows remote attackers to bypass authentication via an HTTP request that contains (1) no Referer header, or (2) a spoofed Referer header that matches an approved domain, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and force the client to download and execute arbitrary files.
0