Show filters
220 Total Results
Displaying 211-220 of 220
Sort by:
Attacker Value
Unknown

CVE-2008-1106

Disclosure Date: June 09, 2008 (last updated October 04, 2023)
The management interface in Akamai Client (formerly Red Swoosh) 3322 and earlier allows remote attackers to bypass authentication via an HTTP request that contains (1) no Referer header, or (2) a spoofed Referer header that matches an approved domain, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and force the client to download and execute arbitrary files.
0
Attacker Value
Unknown

CVE-2008-0916

Disclosure Date: February 22, 2008 (last updated October 04, 2023)
SQL injection vulnerability in the Highwood Design hwdVideoShare (com_hwdvideoshare) 1.1.3 Alpha component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a viewcategory action to index.php.
0
Attacker Value
Unknown

CVE-2006-6113

Disclosure Date: November 28, 2006 (last updated October 04, 2023)
Monkey Boards 0.3.5 allows remote attackers to obtain sensitive information via direct requests to (1) include/admin_auth.inc.php and (2) include/engine/class.compiler.php, which reveals the full path in an error message. NOTE: this issue is only an exposure if the administrator has changed the default script path.
0
Attacker Value
Unknown

CVE-2005-0281

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the web interface in Soldner Secret Wars 30830 allows remote attackers to inject arbitrary web script or HTML via a user message, which is not filtered or quoted when the administrator views the server logs.
0
Attacker Value
Unknown

CVE-2005-0279

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Soldner Secret Wars 30830 and earlier does not properly handle the "message too long" socket error, which allows remote attackers to cause a denial of service (socket termination) via a long UDP packet.
0
Attacker Value
Unknown

CVE-2005-0352

Disclosure Date: March 16, 2005 (last updated February 22, 2025)
Servers Alive 4.1 and 5.0, when running as a service, does not drop SYSTEM privileges before loading local manual under the help menu, which allows local users to gain privileges.
0
Attacker Value
Unknown

CVE-2005-0693

Disclosure Date: March 07, 2005 (last updated February 22, 2025)
Buffer overflow in JoWood Chaser 1.50 and earlier allows remote attackers to cause a denial of service (client or server crash) and execute arbitrary code via a long nickname.
0
Attacker Value
Unknown

CVE-2005-0280

Disclosure Date: January 04, 2005 (last updated February 22, 2025)
Format string vulnerability in Soldner Secret Wars 30830 and earlier allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in a message.
0
Attacker Value
Unknown

CVE-2001-1298

Disclosure Date: October 02, 2001 (last updated February 22, 2025)
Webodex PHP script 1.0 and earlier allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.
0
Attacker Value
Unknown

CVE-2000-0010

Disclosure Date: December 26, 1999 (last updated February 22, 2025)
WebWho+ whois.cgi program allows remote attackers to execute commands via shell metacharacters in the TLD parameter.
0