Show filters
49 Total Results
Displaying 41-49 of 49
Sort by:
Attacker Value
Unknown

CVE-2010-2466

Disclosure Date: June 25, 2010 (last updated October 04, 2023)
The S2 Security NetBox, possibly 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, does not properly prevent downloading of database backups, which allows remote attackers to obtain sensitive information via requests for full_*.dar files with predictable filenames.
0
Attacker Value
Unknown

CVE-2010-2469

Disclosure Date: June 25, 2010 (last updated October 04, 2023)
The Linear eMerge 50 and 5000 uses a default password of eMerge for the IEIeMerge account, which makes it easier for remote attackers to obtain Video Recorder data by establishing a session to the device.
0
Attacker Value
Unknown

CVE-2010-2465

Disclosure Date: June 25, 2010 (last updated October 04, 2023)
The S2 Security NetBox 2.5, 3.3, and 4.0, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download node logs, photographs of persons, and backup files via unspecified HTTP requests.
0
Attacker Value
Unknown

CVE-2009-2442

Disclosure Date: July 13, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in public/index.php in Linea21 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the search parameter in a resultats-recherche action.
0
Attacker Value
Unknown

CVE-2007-4384

Disclosure Date: August 17, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in depouilg.php3 in Stephane Pineau VOTE 1c allow remote attackers to execute arbitrary PHP code via a URL in the (1) NomVote and (2) FilePalHex parameters.
0
Attacker Value
Unknown

CVE-2007-2021

Disclosure Date: April 12, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Pineapple Technologies Lore 1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lang_path parameter to third_party/phpmailer/class.phpmailer.php or the (2) get_plugin_file_path parameter to third_party/smarty/libs/plugins/function.html_checkboxes.php. NOTE: the affected files might be from other software packages, so this might not be a vulnerability in Lore itself. NOTE: (1) might be the same issue as CVE-2006-5734.4.
0
Attacker Value
Unknown

CVE-2007-1905

Disclosure Date: April 10, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in auth.php in Pineapple Technologies QuizShock 1.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via encoded special characters in the forward_to parameter, as demonstrated using "<"<".
0
Attacker Value
Unknown

CVE-2006-2836

Disclosure Date: June 06, 2006 (last updated October 04, 2023)
SQL injection vulnerability in comment.php in Pineapple Technologies Lore 1.5.6 and earlier allows remote attackers to execute arbitrary SQL commands via the article_id parameter.
0
Attacker Value
Unknown

CVE-2005-3988

Disclosure Date: December 04, 2005 (last updated February 22, 2025)
SQL injection vulnerability in article.php in Pineapple Technologies Lore 1.5.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.
0