Show filters
49 Total Results
Displaying 31-40 of 49
Sort by:
Attacker Value
Unknown
CVE-2009-4460
Disclosure Date: December 30, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Auto-Surf Traffic Exchange Script 1.1 allow remote attackers to inject arbitrary web script or HTML via the rid parameter to (1) index.php, (2) faq.php, and (3) register.php.
0
Attacker Value
Unknown
CVE-2008-2002
Disclosure Date: April 28, 2008 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities on Motorola Surfboard with software SB5100-2.3.3.0-SCM00-NOSH allow remote attackers to (1) cause a denial of service (device reboot) via the "Restart Cable Modem" value in the BUTTON_INPUT parameter to configdata.html, and (2) cause a denial of service (hard reset) via the "Reset All Defaults" value in the BUTTON_INPUT parameter to configdata.html.
0
Attacker Value
Unknown
CVE-2006-6992
Disclosure Date: February 09, 2007 (last updated October 04, 2023)
Cross-domain vulnerability in GoSuRF Browser 2.62 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object, a similar vulnerability to CVE-2006-3280.
0
Attacker Value
Unknown
CVE-2006-5196
Disclosure Date: October 10, 2006 (last updated October 04, 2023)
The HTTP interface in the Motorola SURFboard SB4200 Cable Modem allows remote attackers to cause a denial of service (device crash) via a request with MfcISAPICommand set to SecretProc and a long string in the Secret parameter.
0
Attacker Value
Unknown
CVE-2005-1994
Disclosure Date: June 14, 2005 (last updated February 22, 2025)
Finjan SurfinGate 7.0SP2 and SP3 allows remote attackers to download blocked files via hex-encoded characters in a filename, as demonstrated using "%2e".
0
Attacker Value
Unknown
CVE-2004-1780
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Info Touch Surfnet kiosk allows local users to deposit extra time into Internet kiosk accounts via repeated authentication attempts.
0
Attacker Value
Unknown
CVE-2004-2107
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Finjan SurfinGate 6.0 and 7.0, when running in proxy mode, does not authenticate FHTTP commands on TCP port 3141, which allows remote attackers to use the finjan-parameter-type header to (1) restart the service, (2) use the getlastmsg command to view log information, or (3) use the online command to force a policy update from the database server.
0
Attacker Value
Unknown
CVE-2004-2129
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
SurfNOW 2.2 allows remote attackers to cause a denial of service (crash) via a series of long HTTP GET requests, possibly triggering a buffer overflow.
0
Attacker Value
Unknown
CVE-2004-2550
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in unspecified Perl scripts in SandSurfer before 1.7.1 allow remote attackers to inject arbitrary web script or HTML, which is later executed by a target who views reports containing the injected data.
0
Attacker Value
Unknown
CVE-2004-1781
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Info Touch Surfnet kiosk allows local users to crash Surfnet and access the underlying operating system via the CMD_CREDITCARD_CHARGE command.
0