Show filters
251 Total Results
Displaying 211-220 of 251
Sort by:
Attacker Value
Unknown

CVE-2008-3024

Disclosure Date: July 07, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in phgrafx in QNX Momentics (aka RTOS) 6.3.2 and earlier allows local users to gain privileges via a long .pal filename in palette/.
0
Attacker Value
Unknown

CVE-2008-2972

Disclosure Date: July 02, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in KbLance allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a comment action.
0
Attacker Value
Unknown

CVE-2008-1883

Disclosure Date: April 18, 2008 (last updated October 04, 2023)
The server in Blackboard Academic Suite 7.x stores MD5 password hashes that are provided directly by clients, which makes it easier for remote attackers to access accounts via a modified client that skips the javascript/md5.js hash calculation, and instead sends an arbitrary MD5 string.
0
Attacker Value
Unknown

CVE-2008-1795

Disclosure Date: April 15, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Academic Suite 7.x and earlier, and possibly some 8.0 versions, allow remote attackers to inject arbitrary web script or HTML via (1) the searchText parameter in a Course action to webapps/blackboard/execute/viewCatalog or (2) the data__announcements___pk1_pk2__subject parameter in an ADD action to bin/common/announcement.pl.
0
Attacker Value
Unknown

CVE-2007-6105

Disclosure Date: November 23, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in TalkBack 2.2.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) language_file parameter to (a) comments-display-tpl.php and (b) addons/separate-comments-mod/my-comments-display-tpl.php and the (2) config[comments_form_tpl] parameter to comments-display-tpl.php.
0
Attacker Value
Unknown

CVE-2007-5647

Disclosure Date: October 23, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in SocketKB 1.1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) art_id or (2) node parameter in an article action to the default URI.
0
Attacker Value
Unknown

CVE-2007-5227

Disclosure Date: October 05, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in messaging/course/composeMessage.jsp in BlackBoard Learning System 6.3.1.593 and earlier in BlackBoard Academic Suite allow remote attackers to inject arbitrary web script or HTML via the (1) subject_t and (2) body_text parameters. NOTE: vector 2 requires bypassing a client-side security mechanism that attempts to block XSS sequences.
0
Attacker Value
Unknown

CVE-2007-3911

Disclosure Date: July 30, 2007 (last updated October 04, 2023)
Multiple heap-based buffer overflows in (1) clsscheduler.exe (aka scheduler client) and (2) srvscheduler.exe (aka scheduler server) in BakBone NetVault Reporter 3.5 before Update4 allow remote attackers to execute arbitrary code via long filename arguments in HTTP requests.
0
Attacker Value
Unknown

CVE-2007-3181

Disclosure Date: June 12, 2007 (last updated October 04, 2023)
Buffer overflow in fbserver.exe in Firebird SQL 2 before 2.0.1 allows remote attackers to execute arbitrary code via a large p_cnct_count value in a p_cnct structure in a connect (0x01) request to port 3050/tcp, related to "an InterBase version of gds32.dll."
0
Attacker Value
Unknown

CVE-2007-2542

Disclosure Date: May 09, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in header.php in workbench survival guide 0.11 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.
0