Show filters
304 Total Results
Displaying 281-290 of 304
Sort by:
Attacker Value
Unknown

CVE-2008-6613

Disclosure Date: April 06, 2009 (last updated October 04, 2023)
uploader.php in minimal-ablog 0.4 does not properly restrict access, which allows remote attackers to gain administrative privileges via a direct request.
0
Attacker Value
Unknown

CVE-2008-6612

Disclosure Date: April 06, 2009 (last updated October 04, 2023)
Unrestricted file upload vulnerability in admin/uploader.php in Minimal ABlog 0.4 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in img/.
0
Attacker Value
Unknown

CVE-2008-6109

Disclosure Date: February 11, 2009 (last updated October 04, 2023)
Robin Rawson-Tetley Animal Shelter Manager (ASM) before 2.2.2 does not properly enforce the privileges of user accounts, which allows local users to bypass intended access restrictions by (1) opening unspecified screens, related to the "double click selector bug"; or modifying a (2) animal, (3) owner, (4) lost/found, (5) diary note, (6) owner donation, or (7) waiting list record, related to "change permissions" and the "new UI."
0
Attacker Value
Unknown

CVE-2008-3599

Disclosure Date: August 12, 2008 (last updated October 04, 2023)
SQL injection vulnerability in image.php in OpenImpro 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2008-2820

Disclosure Date: June 23, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in lang/lang-system.php in Open Azimyt CMS 0.22 minimal and 0.21 stable allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.
0
Attacker Value
Unknown

CVE-2008-2174

Disclosure Date: May 13, 2008 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in Robin Rawson-Tetley Animal Shelter Manager (ASM) before 2.2.2 have unknown impact and attack vectors, related to "various areas where security was missing."
0
Attacker Value
Unknown

CVE-2008-0732

Disclosure Date: February 12, 2008 (last updated October 04, 2023)
The init script for Apache Geronimo on SUSE Linux follows symlinks when performing a chown operation, which might allow local users to obtain access to unspecified files or directories.
0
Attacker Value
Unknown

CVE-2008-0260

Disclosure Date: January 15, 2008 (last updated October 04, 2023)
minimal Gallery 0.8 allows remote attackers to obtain configuration information via a direct request to php_info.php, which calls the phpinfo function.
0
Attacker Value
Unknown

CVE-2008-0259

Disclosure Date: January 15, 2008 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in _mg/php/mg_thumbs.php in minimal Gallery 0.8 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) thumbcat and (2) thumb parameters.
0
Attacker Value
Unknown

CVE-2007-5797

Disclosure Date: November 03, 2007 (last updated October 04, 2023)
SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass authentication via a login attempt with any username not contained in the database.
0