Show filters
323 Total Results
Displaying 261-270 of 323
Sort by:
Attacker Value
Unknown
CVE-2011-3829
Disclosure Date: January 29, 2012 (last updated October 04, 2023)
ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive information via the file name, which reveals the installation path in an error message.
0
Attacker Value
Unknown
CVE-2011-5071
Disclosure Date: January 29, 2012 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.64 allow remote attackers to execute arbitrary SQL commands via the (1) exc[] parameter to report_marketing.php, (2) selected[] parameter to tasks.php, (3) sites[] parameter to billable_incidents.php, or (4) search_string parameter to search.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2011-5068
Disclosure Date: January 29, 2012 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in Support Incident Tracker (aka SiT!) 3.65 allow remote attackers to hijack the authentication of user for requests that delete a user via user_delete.php and other unspecified programs.
0
Attacker Value
Unknown
CVE-2011-5070
Disclosure Date: January 29, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Support Incident Tracker (aka SiT!) 3.65 allow remote attackers to inject arbitrary web script or HTML via (1) the file name to incident_attachments.php; (2) unspecified vectors in link_add.php, possibly involving origref, linkref, linktype parameters, which are not properly handled in the clean_int function in lib/base.inc.php, or the redirect parameter, which is not properly handled in the html_redirect function in lib/html.inc.php; and (3) unspecified vectors in translate.php.
0
Attacker Value
Unknown
CVE-2011-3832
Disclosure Date: January 29, 2012 (last updated October 04, 2023)
Eval injection vulnerability in config.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated administrators to execute arbitrary PHP code via the application_name parameter in a save action.
0
Attacker Value
Unknown
CVE-2011-3831
Disclosure Date: January 29, 2012 (last updated October 04, 2023)
SQL injection vulnerability in incident_attachments.php in Support Incident Tracker (aka SiT!) 3.65 allows remote attackers to execute arbitrary SQL commands via an uploaded file with a crafted file name.
0
Attacker Value
Unknown
CVE-2011-3830
Disclosure Date: January 29, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in search.php in Support Incident Tracker (aka SiT!) 3.65 allows remote attackers to inject arbitrary web script or HTML via the search_string parameter.
0
Attacker Value
Unknown
CVE-2011-5067
Disclosure Date: January 29, 2012 (last updated October 04, 2023)
move_uploaded_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive information via the file name, which reveals the installation path in an error message.
0
Attacker Value
Unknown
CVE-2010-4926
Disclosure Date: October 09, 2011 (last updated October 04, 2023)
SQL injection vulnerability in the TimeTrack (com_timetrack) component 1.2.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the ct_id parameter in a timetrack action to index.php.
0
Attacker Value
Unknown
CVE-2011-1671
Disclosure Date: April 10, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in app/controllers/todos_controller.rb in Tracks 1.7.2, 2.0RC2, and 2.0devel allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to todos/tag/. NOTE: some of these details are obtained from third party information.
0