Show filters
251 Total Results
Displaying 241-250 of 251
Sort by:
Attacker Value
Unknown
CVE-2005-1108
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
The ij_untrusted_url function in JunkBuster 2.0.2-r2, with single-threaded mode enabled, allows remote attackers to overwrite the referrer field via a crafted HTTP request.
0
Attacker Value
Unknown
CVE-2005-1009
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Multiple buffer overflows in BakBone NetVault 6.x and 7.x allow (1) remote attackers to execute arbitrary code via a modified computer name and length that leads to a heap-based buffer overflow, or (2) local users to execute arbitrary code via a long Name entry in the configure.cfg file.
0
Attacker Value
Unknown
CVE-2005-1109
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
The filtering of URLs in JunkBuster before 2.0.2-r3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via heap corruption.
0
Attacker Value
Unknown
CVE-2004-1582
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in BlackBoard 1.5.1 allows remote attackers to execute arbitrary PHP code by modifying the libpath parameter (incorrectly called "libpach") to reference a URL on a remote web server that contains _more.php, as demonstrated using checkdb.inc.php.
0
Attacker Value
Unknown
CVE-2004-1581
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
BlackBoard 1.5.1 allows remote attackers to gain sensitive information via a direct request to (1) checkdb.inc.php, (2) admin.inc.php or (3) cp.inc.php, which reveals the path in a PHP error message.
0
Attacker Value
Unknown
CVE-2003-1421
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Unspecified vulnerability in mod_mysql_logger shared object in SuckBot 0.006 allows remote attackers to cause a denial of service (seg fault) via unknown attack vectors.
0
Attacker Value
Unknown
CVE-2002-1007
Disclosure Date: October 04, 2002 (last updated February 22, 2025)
Cross-site scripting vulnerabilities in Blackboard 5 allow remote attackers to execute arbitrary web script via (1) the course_id parameter in a link to login.pl, (2) the CTID parameter in ProcessInfo.cgi, or (3) the Message parameter in index.cgi.
0
Attacker Value
Unknown
CVE-2002-0793
Disclosure Date: August 12, 2002 (last updated February 22, 2025)
Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrite arbitrary files via (1) the -f argument to the monitor utility, (2) the -d argument to dumper, (3) the -c argument to crttrap, or (4) using the Watcom sample utility.
0
Attacker Value
Unknown
CVE-2001-0201
Disclosure Date: March 26, 2001 (last updated February 22, 2025)
The Postaci frontend for PostgreSQL does not properly filter characters such as semicolons, which could allow remote attackers to execute arbitrary SQL queries via the deletecontact.php program.
0
Attacker Value
Unknown
CVE-2000-0627
Disclosure Date: July 18, 2000 (last updated February 22, 2025)
BlackBoard CourseInfo 4.0 does not properly authenticate users, which allows local users to modify CourseInfo database information and gain privileges by directly calling the supporting CGI programs such as user_update_passwd.pl and user_update_admin.pl.
0