Show filters
350 Total Results
Displaying 291-300 of 350
Sort by:
Attacker Value
Unknown
CVE-2007-0613
Disclosure Date: January 31, 2007 (last updated October 04, 2023)
The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 does not check for duplicate entries when adding newly discovered available contacts, which allows remote attackers to cause a denial of service (disrupted communication) via a flood of duplicate _presence._tcp mDNS queries.
0
Attacker Value
Unknown
CVE-2007-0519
Disclosure Date: January 26, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in memcp.php in XMB U2U Instant Messenger allows remote authenticated users to inject arbitrary web script or HTML via the recipient field.
0
Attacker Value
Unknown
CVE-2007-0302
Disclosure Date: January 18, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in InstantASP 4.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to (a) Logon.aspx, and the (2) Username and (3) Update parameters to (b) Members1.aspx.
0
Attacker Value
Unknown
CVE-2006-4615
Disclosure Date: September 07, 2006 (last updated October 04, 2023)
Shape Services IM+ Mobile Instant Messenger for Pocket PC 3.10 stores usernames and passwords in plaintext in %PROGRAMFILES%\IMPlus\implus.cfg, which allows local users to obtain sensitive information by reading the file.
0
Attacker Value
Unknown
CVE-2006-4242
Disclosure Date: August 21, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in install.jim.php in the JIM 1.0.1 component for Joomla or Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
0
Attacker Value
Unknown
CVE-2006-2079
Disclosure Date: April 27, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in portfolio.php in Verosky Media Instant Photo Gallery, possibly before 1.0.2, allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.
0
Attacker Value
Unknown
CVE-2006-2080
Disclosure Date: April 27, 2006 (last updated October 04, 2023)
SQL injection vulnerability in portfolio_photo_popup.php in Verosky Media Instant Photo Gallery 1.0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter, which is not cleansed before calling the count_click function in includes/functions/fns_std.php. NOTE: this issue could produce resultant XSS.
0
Attacker Value
Unknown
CVE-2006-2052
Disclosure Date: April 26, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Verosky Media Instant Photo Gallery allows remote attackers to inject arbitrary web script or HTML via the member parameter in a viewpro action in member.php. NOTE: the original report may be inaccurate, since the "viewpro" string does not appear in the source code for version 1.0.2 of the product.
0
Attacker Value
Unknown
CVE-2006-1828
Disclosure Date: April 19, 2006 (last updated October 04, 2023)
SQL injection vulnerability in php121language.php in PHP121 1.4 allows remote attackers to execute arbitrary SQL commands and execute arbitrary code via the sess_username variable, as set by the php121un HTTP COOKIE parameter, which is used in multiple files including php121login.php. NOTE: the code execution occurs because the SQL query results are used in an include statement.
0
Attacker Value
Unknown
CVE-2006-0629
Disclosure Date: February 10, 2006 (last updated February 22, 2025)
Unspecified vulnerability in AOL Instant Messenger (AIM) 5.9.3861 allows user-assisted remote attackers to cause a denial of service (client crash) and possibly execute arbitrary code by tricking the user into requesting Buddy Info about a long screen name, which might cause a buffer overflow.
0