Show filters
333 Total Results
Displaying 251-260 of 333
Sort by:
Attacker Value
Unknown

CVE-2007-0792

Disclosure Date: February 06, 2007 (last updated October 04, 2023)
The mod_perl initialization script in Bugzilla 2.23.3 does not set the Bugzilla Apache configuration to allow .htaccess permissions to override file permissions, which allows remote attackers to obtain the database username and password via a direct request for the localconfig file.
0
Attacker Value
Unknown

CVE-2006-6688

Disclosure Date: December 21, 2006 (last updated October 04, 2023)
Web Automated Perl Portal (WebAPP) 0.9.9.4, and 0.9.9.3.4 Network Edition (NE) (aka WebAPP.NET) allows remote attackers to bypass filtering mechanisms via unknown vectors. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2006-6687

Disclosure Date: December 21, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Web Automated Perl Portal (WebAPP) 0.9.9.4, and 0.9.9.3.4 Network Edition (NE) (aka WebAPP.NET), allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2006-5872

Disclosure Date: December 18, 2006 (last updated October 04, 2023)
login.pl in SQL-Ledger before 2.6.21 and LedgerSMB before 1.1.5 allows remote attackers to execute arbitrary Perl code via the "-e" flag in the script parameter, which is used as an argument to the perl program.
0
Attacker Value
Unknown

CVE-2006-4731

Disclosure Date: September 13, 2006 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in (1) login.pl and (2) admin.pl in (a) SQL-Ledger before 2.6.19 and (b) LedgerSMB before 1.0.0p1 allow remote attackers to execute arbitrary Perl code via an unspecified terminal parameter value containing ../ (dot dot slash).
0
Attacker Value
Unknown

CVE-2006-3813

Disclosure Date: August 11, 2006 (last updated October 04, 2023)
A regression error in the Perl package for Red Hat Enterprise Linux 4 omits the patch for CVE-2005-0155, which allows local users to overwrite arbitrary files with debugging information.
0
Attacker Value
Unknown

CVE-2006-3819

Disclosure Date: July 27, 2006 (last updated October 04, 2023)
Eval injection vulnerability in the configure script in TWiki 4.0.0 through 4.0.4 allows remote attackers to execute arbitrary Perl code via an HTTP POST request containing a parameter name starting with "TYPEOF".
0
Attacker Value
Unknown

CVE-2006-3589

Disclosure Date: July 21, 2006 (last updated October 04, 2023)
vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return code from a Perl chmod function call, which might cause an SSL key file to be created with an unsafe umask that allows local users to read or modify the SSL key.
0
Attacker Value
Unknown

CVE-2006-3207

Disclosure Date: June 24, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in newpost.php in Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the id parameter, as demonstrated by injecting a Perl CGI script using "[NR]" sequences in the message parameter, then calling close.php with modified id and t_id parameters to chmod the script. NOTE: this issue might be resultant from dynamic variable evaluation.
0
Attacker Value
Unknown

CVE-2006-0053

Disclosure Date: April 10, 2006 (last updated October 04, 2023)
Imager (libimager-perl) before 0.50 allows user-assisted attackers to cause a denial of service (segmentation fault) by writing a 2- or 4-channel JPEG image (or a 2-channel TGA image) to a scalar, which triggers a NULL pointer dereference.
0