Show filters
45 Total Results
Displaying 31-40 of 45
Sort by:
Attacker Value
Unknown
CVE-2008-5394
Disclosure Date: December 09, 2008 (last updated October 04, 2023)
/bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrary files via a symlink attack on a temporary file referenced in a line (aka ut_line) field in a utmp entry.
0
Attacker Value
Unknown
CVE-2006-6850
Disclosure Date: December 31, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in include.php in the Roster Module (character_roster) in Shadowed Portal 5.7 allows remote attackers to execute arbitrary PHP code via a URL in the mod_root parameter.
0
Attacker Value
Unknown
CVE-2006-4885
Disclosure Date: September 19, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in Shadowed Portal 5.599 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter in (1) footer.php and (2) header.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information. The bottom.php parameter is already covered by CVE-2006-4826.
0
Attacker Value
Unknown
CVE-2006-4826
Disclosure Date: September 15, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in bottom.php in Shadowed Portal 5.599 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.
0
Attacker Value
Unknown
CVE-2006-4664
Disclosure Date: September 09, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in includes/functions_portal.php in Premod Shadow 2.7.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
0
Attacker Value
Unknown
CVE-2006-4329
Disclosure Date: August 24, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Shadows Rising RPG (Pre-Alpha) 0.0.5b and earlier allow remote attackers to execute arbitrary PHP code via a URL in the CONFIG[gameroot] parameter to (1) core/includes/security.inc.php, (2) core/includes/smarty.inc.php, (3) qcms/includes/smarty.inc.php or (4) qlib/smarty.inc.php.
0
Attacker Value
Unknown
CVE-2006-1174
Disclosure Date: May 28, 2006 (last updated October 04, 2023)
useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which causes the mailbox to be created with unpredictable permissions and possibly allows attackers to read or modify the mailbox.
0
Attacker Value
Unknown
CVE-2006-1844
Disclosure Date: April 19, 2006 (last updated October 04, 2023)
The Debian installer for the (1) shadow 4.0.14 and (2) base-config 2.53.10 packages includes sensitive information in world-readable log files, including preseeded passwords and pppoeconf passwords, which might allow local users to gain privileges.
0
Attacker Value
Unknown
CVE-2006-1701
Disclosure Date: April 11, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Pages module in Shadowed Portal allows remote attackers to inject arbitrary web script or HTML via the page parameter to load.php.
0
Attacker Value
Unknown
CVE-2005-2963
Disclosure Date: October 13, 2005 (last updated February 22, 2025)
The mod_auth_shadow module 1.0 through 1.5 and 2.0 for Apache with AuthShadow enabled uses shadow authentication for all locations that use the require group directive, even when other authentication mechanisms are specified, which might allow remote authenticated users to bypass security restrictions.
0