Show filters
42 Total Results
Displaying 31-40 of 42
Sort by:
Attacker Value
Unknown
CVE-2007-2651
Disclosure Date: May 14, 2007 (last updated October 04, 2023)
Multiple off-by-one errors in VooDoo cIRCle before 1.1.beta27 allow remote attackers to cause a denial of service (connection loss) or possibly execute arbitrary code via a (1) DNS name response of the exact length as a buffer; or a long (2) channel name, (3) partyline channel name, or unspecified vectors in crafted BOTNET packets.
0
Attacker Value
Unknown
CVE-2006-2643
Disclosure Date: May 30, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in Monster Top List (MTL) 1.4 allows remote attackers to inject arbitrary web script or HTML via the user_error_message parameter.
0
Attacker Value
Unknown
CVE-2006-1781
Disclosure Date: April 13, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in functions.php in Circle R Monster Top List (MTL) 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter. NOTE: It was later reported that 1.4.2 and earlier are affected.
0
Attacker Value
Unknown
CVE-2006-0205
Disclosure Date: January 13, 2006 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in Wordcircle 2.17 allow remote attackers to (1) execute arbitrary SQL commands and bypass authentication via the password field in the login action to index.php (involving v_login.php and s_user.php) and (2) have other unknown impact via certain other fields in unspecified scripts.
0
Attacker Value
Unknown
CVE-2006-0204
Disclosure Date: January 13, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Wordcircle 2.17 allow remote attackers to inject arbitrary web script or HTML via (1) the "Course name" field in index.php when the frm parameter has the value "mine" and (2) possibly certain other fields in unspecified scripts.
0
Attacker Value
Unknown
CVE-2005-1326
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Buffer overflow in VooDoo cIRCle BOTNET before 1.0.33 allows remote authenticated attackers to cause a denial of service (client crash) via a crafted packet.
0
Attacker Value
Unknown
CVE-2003-1367
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
The which_access variable for Majordomo 2.0 through 1.94.4, and possibly earlier versions, is set to "open" by default, which allows remote attackers to identify the email addresses of members of mailing lists via a "which" command.
0
Attacker Value
Unknown
CVE-2000-0037
Disclosure Date: December 28, 1999 (last updated February 22, 2025)
Majordomo wrapper allows local users to gain privileges by specifying an alternate configuration file.
0
Attacker Value
Unknown
CVE-2000-0035
Disclosure Date: December 28, 1999 (last updated February 22, 2025)
resend command in Majordomo allows local users to gain privileges via shell metacharacters.
0
Attacker Value
Unknown
CVE-1999-1220
Disclosure Date: August 24, 1997 (last updated February 22, 2025)
Majordomo 1.94.3 and earlier allows remote attackers to execute arbitrary commands when the advertise or noadvertise directive is used in a configuration file, via shell metacharacters in the Reply-To header.
0