Show filters
60 Total Results
Displaying 41-50 of 60
Sort by:
Attacker Value
Unknown
CVE-2013-3578
Disclosure Date: July 15, 2013 (last updated October 05, 2023)
SQL injection vulnerability in the Help Desk application in Wave EMBASSY Remote Administration Server (ERAS) allows remote authenticated users to execute arbitrary SQL commands via the ct100$4MainController$TextBoxSearchValue parameter (aka the search field), leading to execution of operating-system commands.
0
Attacker Value
Unknown
CVE-2013-2765
Disclosure Date: July 15, 2013 (last updated October 05, 2023)
The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process crash, and disk consumption) via a POST request with a large body and a crafted Content-Type header.
0
Attacker Value
Unknown
CVE-2013-1915
Disclosure Date: April 25, 2013 (last updated October 05, 2023)
ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) vulnerability.
0
Attacker Value
Unknown
CVE-2012-4528
Disclosure Date: December 28, 2012 (last updated October 05, 2023)
The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes the crafted data.
0
Attacker Value
Unknown
CVE-2012-4482
Disclosure Date: October 31, 2012 (last updated October 05, 2023)
The Ubercart SecureTrading Payment Method module 6.x for Drupal does not properly verify payment notification information, which allows remote attackers to purchase an item without paying via unspecified vectors.
0
Attacker Value
Unknown
CVE-2009-5031
Disclosure Date: July 22, 2012 (last updated October 04, 2023)
ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks via a single quote in a request parameter in the Content-Disposition field of a request with a multipart/form-data Content-Type header.
0
Attacker Value
Unknown
CVE-2012-2751
Disclosure Date: July 22, 2012 (last updated November 08, 2023)
ModSecurity before 2.6.6, when used with PHP, does not properly handle single quotes not at the beginning of a request parameter value in the Content-Disposition field of a request with a multipart/form-data Content-Type header, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-5031.
0
Attacker Value
Unknown
CVE-2011-2386
Disclosure Date: June 08, 2011 (last updated October 04, 2023)
VisiWaveReport.exe in AZO Technologies, Inc. VisiWave Site Survey before 2.1.9 allows user-assisted remote attackers to execute arbitrary code via a (1) vws and (2) vwr file with an invalid Type property, which triggers an untrusted pointer dereference.
0
Attacker Value
Unknown
CVE-2011-1906
Disclosure Date: May 05, 2011 (last updated October 04, 2023)
Trustwave WebDefend Enterprise before 5.0 7.01.903-1.4 stores specific user-account credentials in a MySQL database, which makes it easier for remote attackers to read the event collection table via requests to the management port, a different vulnerability than CVE-2011-0756.
0
Attacker Value
Unknown
CVE-2011-0756
Disclosure Date: May 05, 2011 (last updated October 04, 2023)
The application server in Trustwave WebDefend Enterprise before 5.0 uses hardcoded console credentials, which makes it easier for remote attackers to read security-event data by using the remote console GUI to connect to the management port.
0