Show filters
323 Total Results
Displaying 281-290 of 323
Sort by:
Attacker Value
Unknown
CVE-2008-3784
Disclosure Date: August 26, 2008 (last updated October 04, 2023)
SQL injection vulnerability in scrape.php in BtiTracker 1.4.7 and earlier and xBtiTracker 2.0.542 and earlier allows remote attackers to execute arbitrary SQL commands via the info_hash parameter.
0
Attacker Value
Unknown
CVE-2008-3429
Disclosure Date: July 31, 2008 (last updated October 04, 2023)
Buffer overflow in URI processing in HTTrack and WinHTTrack before 3.42-3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long URL.
0
Attacker Value
Unknown
CVE-2008-3250
Disclosure Date: July 21, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in Arctic Issue Tracker 2.0.0 allows remote attackers to execute arbitrary SQL commands via the filter parameter.
0
Attacker Value
Unknown
CVE-2008-1474
Disclosure Date: March 24, 2008 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in Roundup before 1.4.4 have unknown impact and attack vectors, some of which may be related to cross-site scripting (XSS).
0
Attacker Value
Unknown
CVE-2008-1475
Disclosure Date: March 24, 2008 (last updated October 04, 2023)
The xml-rpc server in Roundup 1.4.4 does not check property permissions, which allows attackers to bypass restrictions and edit or read restricted properties via the (1) list, (2) display, and (3) set methods.
0
Attacker Value
Unknown
CVE-2008-0336
Disclosure Date: January 17, 2008 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in BugTracker.NET before 2.7.2 allow remote attackers to delete arbitrary bugs and perform other administrative tasks via unspecified vectors, possibly related to delete_*.aspx pages, and massedit.aspx, subscribe.aspx, flag.aspx, and relationships.aspx.
0
Attacker Value
Unknown
CVE-2008-0335
Disclosure Date: January 17, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in BugTracker.NET before 2.7.2 allows remote attackers to inject arbitrary web script or HTML via an arbitrary custom text field.
0
Attacker Value
Unknown
CVE-2007-5987
Disclosure Date: November 15, 2007 (last updated October 04, 2023)
details.php in BtiTracker before 1.4.5, when torrent viewing is disabled for guests, allows remote attackers to bypass protection mechanisms via a direct request, as demonstrated by (1) reading the details of an arbitrary torrent and (2) modifying a torrent owned by a guest.
0
Attacker Value
Unknown
CVE-2007-5985
Disclosure Date: November 15, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in BtiTracker before 1.4.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) account.php, (2) moresmiles.php, or (3) recover.php; or (4) the "to" parameter to usercp.php.
0
Attacker Value
Unknown
CVE-2007-5988
Disclosure Date: November 15, 2007 (last updated October 04, 2023)
blocks/shoutbox_block.php in BtiTracker 1.4.4 does not verify user accounts, which allows remote attackers to post shoutbox entries as arbitrary users via a modified nick field.
0