Show filters
559 Total Results
Displaying 431-440 of 559
Sort by:
Attacker Value
Unknown
CVE-2008-2689
Disclosure Date: June 13, 2008 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in pub/clients.php in BrowserCRM 5.002.00 allows remote attackers to execute arbitrary PHP code via a URL in the bcrm_pub_root parameter.
0
Attacker Value
Unknown
CVE-2008-2690
Disclosure Date: June 13, 2008 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in BrowserCRM 5.002.00, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the bcrm_pub_root parameter to (1) kb.php, (2) login.php, (3) index.php, (4) contact_view.php, and (5) contact.php in pub/, different vectors than CVE-2008-2689. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2008-1762
Disclosure Date: April 12, 2008 (last updated October 04, 2023)
Opera before 9.27 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted scaled image pattern in an HTML CANVAS element, which triggers memory corruption.
0
Attacker Value
Unknown
CVE-2008-1082
Disclosure Date: February 29, 2008 (last updated October 04, 2023)
Opera before 9.26 allows remote attackers to "bypass sanitization filters" and conduct cross-site scripting (XSS) attacks via crafted attribute values in an XML document, which are not properly handled during DOM presentation.
0
Attacker Value
Unknown
CVE-2008-1080
Disclosure Date: February 29, 2008 (last updated October 04, 2023)
Opera before 9.26 allows user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename into a file input.
0
Attacker Value
Unknown
CVE-2008-1081
Disclosure Date: February 29, 2008 (last updated October 04, 2023)
Opera before 9.26 allows user-assisted remote attackers to execute arbitrary script via images that contain custom comments, which are treated as script when the user displays the image properties.
0
Attacker Value
Unknown
CVE-2007-6517
Disclosure Date: December 24, 2007 (last updated October 04, 2023)
SQL injection vulnerability in the forget password section (LostPwd.asp) in Eagle Software Aeries Browser Interface (ABI) 3.7.9.17 allows remote attackers to execute arbitrary SQL commands via the EmailAddress parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2007-6520
Disclosure Date: December 24, 2007 (last updated October 04, 2023)
Opera before 9.25 allows remote attackers to conduct cross-domain scripting attacks via unknown vectors related to plug-ins.
0
Attacker Value
Unknown
CVE-2007-6522
Disclosure Date: December 24, 2007 (last updated October 04, 2023)
The rich text editing functionality in Opera before 9.25 allows remote attackers to conduct cross-domain scripting attacks by using designMode to modify contents of pages in other domains.
0
Attacker Value
Unknown
CVE-2007-6523
Disclosure Date: December 24, 2007 (last updated October 04, 2023)
Algorithmic complexity vulnerability in Opera 9.50 beta and 9.x before 9.25 allows remote attackers to cause a denial of service (CPU consumption) via a crafted bitmap (BMP) file that triggers a large number of calculations and checks.
0