Show filters
267 Total Results
Displaying 251-260 of 267
Sort by:
Attacker Value
Unknown
CVE-2010-0711
Disclosure Date: February 25, 2010 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in default.asp in ASPCode CMS 1.5.8, 2.0.0 Build 103, and possibly other versions, allows remote attackers to hijack the authentication of an administrator for requests that (1) delete users via the delete action in the ma2 parameter or (2) create administrators via the update action in the ma2 parameter.
0
Attacker Value
Unknown
CVE-2009-3806
Disclosure Date: October 27, 2009 (last updated October 04, 2023)
SQL injection vulnerability in feedback_js.php in DedeCMS 5.1 allows remote attackers to execute arbitrary SQL commands via the arcurl parameter.
0
Attacker Value
Unknown
CVE-2009-2963
Disclosure Date: August 25, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the update feature in Toolbar Uninstaller 1.0.2 allows remote attackers to force the download and execution of arbitrary files via attack vectors related to a "malformed update url and a malformed update website."
0
Attacker Value
Unknown
CVE-2009-2270
Disclosure Date: July 01, 2009 (last updated October 04, 2023)
Unrestricted file upload vulnerability in member/uploads_edit.php in dedecms 5.3 allows remote attackers to execute arbitrary code by uploading a file with a double extension in the filename, then accessing this file via unspecified vectors, as demonstrated by a .jpg.php filename.
0
Attacker Value
Unknown
CVE-2009-2018
Disclosure Date: June 09, 2009 (last updated October 04, 2023)
SQL injection vulnerability in admin/index.php in Jared Eckersley MyCars, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the authuserid parameter.
0
Attacker Value
Unknown
CVE-2008-6080
Disclosure Date: February 06, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in download.php in the ionFiles (com_ionfiles) 4.4.2 component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
0
Attacker Value
Unknown
CVE-2008-3796
Disclosure Date: August 27, 2008 (last updated October 04, 2023)
Swfdec 0.6 before 0.6.8 allows remote attackers to cause a denial of service (application crash) via a 1x1 JPEG image.
0
Attacker Value
Unknown
CVE-2008-1834
Disclosure Date: April 16, 2008 (last updated October 04, 2023)
swfdec_load_object.c in Swfdec before 0.6.4 does not properly restrict local file access from untrusted sandboxes, which allows remote attackers to read arbitrary files via a crafted Flash file.
0
Attacker Value
Unknown
CVE-2008-0609
Disclosure Date: February 06, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in DivideConcept VHD Web Pack 2.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.
0
Attacker Value
Unknown
CVE-2006-4537
Disclosure Date: September 05, 2006 (last updated October 04, 2023)
NET$SESSION_CONTROL.EXE in DECnet-Plus in OpenVMS ALPHA 7.3-2 and Alpha 8.2 writes a password to an audit log file when there is a successful connection after a "network breakin" event, which allows local users to obtain passwords by reading the file.
0