Show filters
323 Total Results
Displaying 271-280 of 323
Sort by:
Attacker Value
Unknown

CVE-2010-4537

Disclosure Date: January 13, 2011 (last updated October 04, 2023)
Unspecified vulnerability in CrawlTrack before 3.2.7, when a public stats page is provided, allows remote attackers to execute arbitrary PHP code via unknown vectors.
0
Attacker Value
Unknown

CVE-2010-2491

Disclosure Date: September 24, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.14 allows remote attackers to inject arbitrary web script or HTML via the template argument to the /issue program.
0
Attacker Value
Unknown

CVE-2010-2801

Disclosure Date: August 09, 2010 (last updated October 04, 2023)
Integer signedness error in the Quantum decompressor in cabextract before 1.3, when archive test mode is used, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Quantum archive in a .cab file, related to the libmspack library.
0
Attacker Value
Unknown

CVE-2010-2800

Disclosure Date: August 09, 2010 (last updated October 04, 2023)
The MS-ZIP decompressor in cabextract before 1.3 allows remote attackers to cause a denial of service (infinite loop) via a malformed MSZIP archive in a .cab file during a (1) test or (2) extract action, related to the libmspack library.
0
Attacker Value
Unknown

CVE-2010-1596

Disclosure Date: April 28, 2010 (last updated October 04, 2023)
Support Incident Tracker before 3.51, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.
0
Attacker Value
Unknown

CVE-2010-1543

Disclosure Date: April 26, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the eTracker module before 6.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML by appending a crafted string to an arbitrary URL associated with the Drupal site.
0
Attacker Value
Unknown

CVE-2010-1053

Disclosure Date: March 23, 2010 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Zen Time Tracking 2.2 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters to (a) userlogin.php and (b) managerlogin.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-6088

Disclosure Date: February 06, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the Joomtracker (com_joomtracker) 1.01 module for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a tordetails action to index.php.
0
Attacker Value
Unknown

CVE-2008-5646

Disclosure Date: December 17, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Trac before 0.11.2 allows attackers to cause a denial of service via unknown attack vectors related to "certain wiki markup."
0
Attacker Value
Unknown

CVE-2008-5647

Disclosure Date: December 17, 2008 (last updated October 04, 2023)
Unspecified vulnerability in the HTML sanitizer filter in Trac before 0.11.2 allows attackers to conduct phishing attacks via unknown attack vectors.
0