Show filters
49 Total Results
Displaying 31-40 of 49
Sort by:
Attacker Value
Unknown

CVE-2015-5303

Disclosure Date: April 11, 2016 (last updated November 25, 2024)
The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter.
0
Attacker Value
Unknown

CVE-2015-4659

Disclosure Date: June 18, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in ClickHeat 1.14 and earlier allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via a config action to index.php.
0
Attacker Value
Unknown

CVE-2014-3801

Disclosure Date: May 23, 2014 (last updated October 05, 2023)
OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider template URL via the resource-type-list.
0
Attacker Value
Unknown

CVE-2013-6426

Disclosure Date: December 14, 2013 (last updated October 05, 2023)
The cloudformation-compatible API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 does not properly enforce policy rules, which allows local in-instance users to bypass intended access restrictions and (1) create a stack via the CreateStack method or (2) update a stack via the UpdateStack method.
0
Attacker Value
Unknown

CVE-2013-6428

Disclosure Date: December 14, 2013 (last updated October 05, 2023)
The ReST API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 allows remote authenticated users to bypass the tenant scoping restrictions via a modified tenant_id in the request path.
0
Attacker Value
Unknown

CVE-2009-3642

Disclosure Date: October 09, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in the Call Logging feature in FrontRange HEAT 8.01 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
0
Attacker Value
Unknown

CVE-2008-6244

Disclosure Date: February 23, 2009 (last updated October 04, 2023)
SQL injection vulnerability in view_reviews.php in Scripts for Sites (SFS) EZ Gaming Cheats allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2008-5793

Disclosure Date: December 31, 2008 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in the Clickheat - Heatmap stats (com_clickheat) component 1.0.1 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[mosConfig_absolute_path] parameter to (a) install.clickheat.php, (b) Cache.php and (c) Clickheat_Heatmap.php in Recly/Clickheat/, and (d) Recly/common/GlobalVariables.php; and the (2) mosConfig_absolute_path parameter to (e) _main.php and (f) main.php in includes/heatmap, and (g) includes/overview/main.php.
0
Attacker Value
Unknown

CVE-2008-5170

Disclosure Date: November 19, 2008 (last updated October 04, 2023)
SQL injection vulnerability in item.php in Cheats Complete Website 1.1.1 allows remote attackers to execute arbitrary SQL commands via the itemid parameter.
0
Attacker Value
Unknown

CVE-2008-1863

Disclosure Date: April 17, 2008 (last updated October 04, 2023)
SQL injection vulnerability in view_reviews.php in Prozilla Cheat Script (aka Cheats) 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
0