Show filters
323 Total Results
Displaying 281-290 of 323
Sort by:
Attacker Value
Unknown

CVE-2008-3784

Disclosure Date: August 26, 2008 (last updated October 04, 2023)
SQL injection vulnerability in scrape.php in BtiTracker 1.4.7 and earlier and xBtiTracker 2.0.542 and earlier allows remote attackers to execute arbitrary SQL commands via the info_hash parameter.
0
Attacker Value
Unknown

CVE-2008-3429

Disclosure Date: July 31, 2008 (last updated October 04, 2023)
Buffer overflow in URI processing in HTTrack and WinHTTrack before 3.42-3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long URL.
0
Attacker Value
Unknown

CVE-2008-3250

Disclosure Date: July 21, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in Arctic Issue Tracker 2.0.0 allows remote attackers to execute arbitrary SQL commands via the filter parameter.
0
Attacker Value
Unknown

CVE-2008-1474

Disclosure Date: March 24, 2008 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in Roundup before 1.4.4 have unknown impact and attack vectors, some of which may be related to cross-site scripting (XSS).
0
Attacker Value
Unknown

CVE-2008-1475

Disclosure Date: March 24, 2008 (last updated October 04, 2023)
The xml-rpc server in Roundup 1.4.4 does not check property permissions, which allows attackers to bypass restrictions and edit or read restricted properties via the (1) list, (2) display, and (3) set methods.
0
Attacker Value
Unknown

CVE-2008-0336

Disclosure Date: January 17, 2008 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in BugTracker.NET before 2.7.2 allow remote attackers to delete arbitrary bugs and perform other administrative tasks via unspecified vectors, possibly related to delete_*.aspx pages, and massedit.aspx, subscribe.aspx, flag.aspx, and relationships.aspx.
0
Attacker Value
Unknown

CVE-2008-0335

Disclosure Date: January 17, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in BugTracker.NET before 2.7.2 allows remote attackers to inject arbitrary web script or HTML via an arbitrary custom text field.
0
Attacker Value
Unknown

CVE-2007-5987

Disclosure Date: November 15, 2007 (last updated October 04, 2023)
details.php in BtiTracker before 1.4.5, when torrent viewing is disabled for guests, allows remote attackers to bypass protection mechanisms via a direct request, as demonstrated by (1) reading the details of an arbitrary torrent and (2) modifying a torrent owned by a guest.
0
Attacker Value
Unknown

CVE-2007-5985

Disclosure Date: November 15, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in BtiTracker before 1.4.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) account.php, (2) moresmiles.php, or (3) recover.php; or (4) the "to" parameter to usercp.php.
0
Attacker Value
Unknown

CVE-2007-5988

Disclosure Date: November 15, 2007 (last updated October 04, 2023)
blocks/shoutbox_block.php in BtiTracker 1.4.4 does not verify user accounts, which allows remote attackers to post shoutbox entries as arbitrary users via a modified nick field.
0