Show filters
664 Total Results
Displaying 401-410 of 664
Sort by:
Attacker Value
Unknown

CVE-2008-6956

Disclosure Date: August 12, 2009 (last updated October 04, 2023)
Static code injection vulnerability in admin/admin.php in mxCamArchive 2.2 allows remote authenticated administrators to inject arbitrary PHP code into an unspecified program via the description parameter, which is executed by invocation of index.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-6955

Disclosure Date: August 12, 2009 (last updated October 04, 2023)
mxCamArchive 2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain configuration details and passwords via a direct request for archive/config.ini.
0
Attacker Value
Unknown

CVE-2009-2534

Disclosure Date: July 20, 2009 (last updated October 04, 2023)
RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allow remote attackers to cause a denial of service (daemon crash) via an RTSP SETUP request that (1) specifies the / URI or (2) lacks a / character in the URI.
0
Attacker Value
Unknown

CVE-2009-2533

Disclosure Date: July 20, 2009 (last updated October 04, 2023)
rmserver in RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allows remote attackers to cause a denial of service (daemon exit) via multiple RTSP SET_PARAMETER requests with empty DataConvertBuffer headers.
0
Attacker Value
Unknown

CVE-2009-1751

Disclosure Date: May 22, 2009 (last updated October 04, 2023)
SQL injection vulnerability in list_list.php in Realty Webware Technologies Web-Base 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2009-1658

Disclosure Date: May 18, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in admin/admin.php in Realty Webware Technologies Realty Web-Base 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) user (username) and (2) password parameters. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2009-1596

Disclosure Date: May 11, 2009 (last updated February 14, 2024)
Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which allows remote authenticated users to bypass intended policy and change their own passwords via a passwd_change IQ packet.
Attacker Value
Unknown

CVE-2009-1595

Disclosure Date: May 11, 2009 (last updated October 04, 2023)
The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a passwd_change action.
0
Attacker Value
Unknown

CVE-2008-6510

Disclosure Date: March 23, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in login.jsp in the Admin Console in Openfire 3.6.0a and earlier allows remote attackers to inject arbitrary web script or HTML via the url parameter.
0
Attacker Value
Unknown

CVE-2008-6511

Disclosure Date: March 23, 2009 (last updated October 04, 2023)
Open redirect vulnerability in login.jsp in Openfire 3.6.0a and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter.
0