Show filters
37 Total Results
Displaying 31-37 of 37
Sort by:
Attacker Value
Unknown
CVE-2008-1797
Disclosure Date: April 15, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Secure Computing Webwasher 5.30 before build 3159 and 6.3.0 before build 3150 allows remote attackers to cause a denial of service (freeze) via a crafted URL.
0
Attacker Value
Unknown
CVE-2008-0837
Disclosure Date: February 20, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the log feature in the John Godley Search Unleashed 0.2.10 plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter, which is not properly handled when the administrator views the log file.
0
Attacker Value
Unknown
CVE-2007-3275
Disclosure Date: June 19, 2007 (last updated October 04, 2023)
MailWasher Server before 2.2.1, when used with LDAP or Active Directory (AD), does not properly handle blank passwords, which allows remote attackers to access an arbitrary user account and read the spam e-mail messages stored for that account, possibly related to the LoginCheck::doPost function in mwi/servlet/Login.cpp. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2006-6067
Disclosure Date: November 22, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in 20/20 DataShed (aka Real Estate Listing System) allow remote attackers to execute arbitrary SQL commands via the (1) itemID parameter to (a) f-email.asp, or the (2) peopleID and (2) sort_order parameters to (b) listings.asp, different vectors than CVE-2006-5955.
0
Attacker Value
Unknown
CVE-2006-5955
Disclosure Date: November 17, 2006 (last updated October 04, 2023)
SQL injection vulnerability in listings.asp in 20/20 DataShed (aka Real Estate Listing System) allows remote attackers to execute arbitrary SQL commands via the itemID parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2005-0316
Disclosure Date: January 28, 2005 (last updated February 22, 2025)
WebWasher Classic 2.2.1 and 3.3, when running in server mode, does not properly drop CONNECT requests to the localhost from external systems, which could allow remote attackers to bypass intended access restrictions.
0
Attacker Value
Unknown
CVE-2003-1474
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
slashem-tty in the FreeBSD Ports Collection is installed with write permissions for the games group, which allows local users with group games privileges to modify slashem-tty and execute arbitrary code as other users, as demonstrated using a separate vulnerability in LTris.
0