Show filters
37 Total Results
Displaying 31-37 of 37
Sort by:
Attacker Value
Unknown
CVE-2007-5644
Disclosure Date: October 23, 2007 (last updated October 04, 2023)
Lussumo Vanilla 1.1.3 and earlier does not require admin privileges for (1) ajax/sortcategories.php and (2) ajax/sortroles.php, which allows remote attackers to conduct unauthorized sort operations and other activities.
0
Attacker Value
Unknown
CVE-2007-5643
Disclosure Date: October 23, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Lussumo Vanilla 1.1.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the CategoryID parameter to ajax/sortcategories.php or (2) an unspecified vector to ajax/sortroles.php.
0
Attacker Value
Unknown
CVE-2007-1251
Disclosure Date: March 03, 2007 (last updated October 04, 2023)
Format string vulnerability in the new_warning function in ntserv/warning.c for Netrek Vanilla Server 2.12.0, when EVENTLOG is enabled, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in the message handling.
0
Attacker Value
Unknown
CVE-2006-3850
Disclosure Date: July 25, 2006 (last updated November 08, 2023)
PHP remote file inclusion vulnerability in upgrader.php in Vanilla CMS 1.0.1 and earlier, when /conf/old_settings.php exists, allows remote attackers to execute arbitrary PHP code via a URL in the RootDirectory parameter. NOTE: this issue has been disputed by a third party who states that the RootDirectory parameter is initialized before being used, for version 1.0. CVE analysis concurs with the dispute, but it is unclear whether older versions are affected
0
Attacker Value
Unknown
CVE-2006-2990
Disclosure Date: June 13, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in default.asp in VanillaSoft Helpdesk 2005 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter.
0
Attacker Value
Unknown
CVE-2006-0540
Disclosure Date: February 04, 2006 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in Tachyon Vanilla Guestbook 1.0 beta allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2006-0541
Disclosure Date: February 04, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Tachyon Vanilla Guestbook 1.0 beta allow remote attackers to inject arbitrary web script or HTML via unknown vectors related to "posting new messages."
0