Show filters
40 Total Results
Displaying 31-40 of 40
Sort by:
Attacker Value
Unknown

CVE-2006-3340

Disclosure Date: July 03, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Pearl For Mambo module 1.6 for Mambo, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via the (1) phpbb_root_path parameter in (a) includes/functions_cms.php and the (2) GlobalSettings[templatesDirectory] parameter in multiple files in the "includes" directory including (b) adminSensored.php, (c) adminBoards.php, (d) adminAttachments.php, (e) adminAvatars.php, (f) adminBackupdatabase.php, (g) adminBanned.php, (h) adminForums.php, (i) adminPolls.php, (j) adminSmileys.php, (k) poll.php, and (l) move.php.
0
Attacker Value
Unknown

CVE-2006-0931

Disclosure Date: February 28, 2006 (last updated February 22, 2025)
Directory traversal vulnerability in PEAR::Archive_Tar 1.2, and other versions before 1.3.2, allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a TAR archive.
0
Attacker Value
Unknown

CVE-2006-0932

Disclosure Date: February 28, 2006 (last updated February 22, 2025)
Directory traversal vulnerability in zip.lib.php 0.1.1 in PEAR::Archive_Zip allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a ZIP archive.
0
Attacker Value
Unknown

CVE-2006-0868

Disclosure Date: February 23, 2006 (last updated February 22, 2025)
Multiple unspecified injection vulnerabilities in unspecified Auth Container back ends for PEAR::Auth before 1.2.4, and 1.3.x before 1.3.0r4, allow remote attackers to "falsify authentication credentials," related to the "underlying storage containers."
0
Attacker Value
Unknown

CVE-2006-0869

Disclosure Date: February 23, 2006 (last updated February 22, 2025)
Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0.16.8 and earlier allows remote attackers to determine file existence, and possibly delete arbitrary files with short pathnames or possibly read arbitrary files, via a .. (dot dot) in the store_id value of a cookie.
0
Attacker Value
Unknown

CVE-2005-4730

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Unspecified vulnerability in PEAR Text_Password 1.0 has unknown impact and attack vectors, related to "problematic seeding" of the random number generator, possibly predictable seeds.
0
Attacker Value
Unknown

CVE-2005-4646

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Unspecified vulnerability in index.php in PEARLINGER Pearl Forums 2.4 allows remote attackers to include arbitrary files via the mode parameter, possibly due to a directory traversal vulnerability. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2005-4647

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in PEARLINGER Pearl Forums 2.4 allow remote attackers to execute arbitrary SQL commands via the (1) forumsId and (2) topicId parameters in index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2005-4493

Disclosure Date: December 22, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in SpearTek 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.
0
Attacker Value
Unknown

CVE-2001-0530

Disclosure Date: August 14, 2001 (last updated February 22, 2025)
Spearhead NetGAP 200 and 300 before build 78 allow a remote attacker to bypass file blocking and content inspection via specially encoded URLs which include '%' characters.
0