Show filters
102 Total Results
Displaying 31-40 of 102
Sort by:
Attacker Value
Unknown

CVE-2014-6289

Disclosure Date: October 03, 2014 (last updated October 05, 2023)
The Ajax dispatcher for Extbase in the Yet Another Gallery (yag) extension before 3.0.1 and Tools for Extbase development (pt_extbase) extension before 1.5.1 allows remote attackers to bypass access restrictions and execute arbitrary controller actions via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-1062

Disclosure Date: October 03, 2013 (last updated October 05, 2023)
ubuntu-system-service 0.2.4 before 0.2.4.1. 0.2.3 before 0.2.3.1, and 0.2.2 before 0.2.2.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
0
Attacker Value
Unknown

CVE-2013-4681

Disclosure Date: June 25, 2013 (last updated October 05, 2023)
SQL injection vulnerability in the sofortueberweisung2commerce extension before 2.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-0175

Disclosure Date: April 25, 2013 (last updated October 05, 2023)
multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156.
0
Attacker Value
Unknown

CVE-2012-5342

Disclosure Date: October 09, 2012 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in SenseSites CommonSense CMS allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) special.php, (2) article.php, or (3) cat2.php.
0
Attacker Value
Unknown

CVE-2011-4945

Disclosure Date: October 01, 2012 (last updated October 05, 2023)
PolicyKit 0.103 sets the AdminIdentities to "wheel" by default, which allows local users in the wheel group to gain root privileges without authentication.
0
Attacker Value
Unknown

CVE-2012-2395

Disclosure Date: June 16, 2012 (last updated October 04, 2023)
Incomplete blacklist vulnerability in action_power.py in Cobbler 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) username or (2) password fields to the power_system method in the xmlrpc API.
0
Attacker Value
Unknown

CVE-2010-5037

Disclosure Date: November 02, 2011 (last updated October 04, 2023)
SQL injection vulnerability in article.php in SenseSites CommonSense CMS allows remote attackers to execute arbitrary SQL commands via the article_id parameter.
0
Attacker Value
Unknown

CVE-2011-3705

Disclosure Date: September 23, 2011 (last updated October 04, 2023)
Arctic Fox CMS 0.9.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by acp/includes/edit.inc.php and certain other files.
0
Attacker Value
Unknown

CVE-2011-0728

Disclosure Date: March 29, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in templatefunctions.py in Loggerhead before 1.18.1 allows remote authenticated users to inject arbitrary web script or HTML via a filename, which is not properly handled in a revision view.
0