Show filters
220 Total Results
Displaying 211-220 of 220
Sort by:
Attacker Value
Unknown
CVE-2008-1106
Disclosure Date: June 09, 2008 (last updated October 04, 2023)
The management interface in Akamai Client (formerly Red Swoosh) 3322 and earlier allows remote attackers to bypass authentication via an HTTP request that contains (1) no Referer header, or (2) a spoofed Referer header that matches an approved domain, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and force the client to download and execute arbitrary files.
0
Attacker Value
Unknown
CVE-2008-0916
Disclosure Date: February 22, 2008 (last updated October 04, 2023)
SQL injection vulnerability in the Highwood Design hwdVideoShare (com_hwdvideoshare) 1.1.3 Alpha component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a viewcategory action to index.php.
0
Attacker Value
Unknown
CVE-2006-6113
Disclosure Date: November 28, 2006 (last updated October 04, 2023)
Monkey Boards 0.3.5 allows remote attackers to obtain sensitive information via direct requests to (1) include/admin_auth.inc.php and (2) include/engine/class.compiler.php, which reveals the full path in an error message. NOTE: this issue is only an exposure if the administrator has changed the default script path.
0
Attacker Value
Unknown
CVE-2005-0281
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the web interface in Soldner Secret Wars 30830 allows remote attackers to inject arbitrary web script or HTML via a user message, which is not filtered or quoted when the administrator views the server logs.
0
Attacker Value
Unknown
CVE-2005-0279
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Soldner Secret Wars 30830 and earlier does not properly handle the "message too long" socket error, which allows remote attackers to cause a denial of service (socket termination) via a long UDP packet.
0
Attacker Value
Unknown
CVE-2005-0352
Disclosure Date: March 16, 2005 (last updated February 22, 2025)
Servers Alive 4.1 and 5.0, when running as a service, does not drop SYSTEM privileges before loading local manual under the help menu, which allows local users to gain privileges.
0
Attacker Value
Unknown
CVE-2005-0693
Disclosure Date: March 07, 2005 (last updated February 22, 2025)
Buffer overflow in JoWood Chaser 1.50 and earlier allows remote attackers to cause a denial of service (client or server crash) and execute arbitrary code via a long nickname.
0
Attacker Value
Unknown
CVE-2005-0280
Disclosure Date: January 04, 2005 (last updated February 22, 2025)
Format string vulnerability in Soldner Secret Wars 30830 and earlier allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in a message.
0
Attacker Value
Unknown
CVE-2001-1298
Disclosure Date: October 02, 2001 (last updated February 22, 2025)
Webodex PHP script 1.0 and earlier allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.
0
Attacker Value
Unknown
CVE-2000-0010
Disclosure Date: December 26, 1999 (last updated February 22, 2025)
WebWho+ whois.cgi program allows remote attackers to execute commands via shell metacharacters in the TLD parameter.
0