Show filters
530 Total Results
Displaying 431-440 of 530
Sort by:
Attacker Value
Unknown

CVE-2008-2374

Disclosure Date: July 07, 2008 (last updated February 14, 2024)
src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields in SDP packets, which allows remote SDP servers to cause a denial of service or possibly have unspecified other impact via a crafted length field that triggers excessive memory allocation or a buffer over-read.
0
Attacker Value
Unknown

CVE-2008-2921

Disclosure Date: June 30, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in EZTechhelp EZCMS 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter.
0
Attacker Value
Unknown

CVE-2008-2920

Disclosure Date: June 30, 2008 (last updated October 04, 2023)
admin/filemanager/ (aka the File Manager) in EZTechhelp EZCMS 1.2 and earlier does not require authentication, which allows remote attackers to create, modify, read, and delete files.
0
Attacker Value
Unknown

CVE-2008-2217

Disclosure Date: May 14, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in cm/graphie.php in Content Management System 0.6.1 for Phprojekt allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cm_imgpath parameter.
0
Attacker Value
Unknown

CVE-2008-2116

Disclosure Date: May 08, 2008 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to read arbitrary local files via a .. (dot dot) in the (1) te and (2) dir parameters in a tempedit action.
0
Attacker Value
Unknown

CVE-2008-2115

Disclosure Date: May 08, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) te and (2) dir parameters in a tempedit action.
0
Attacker Value
Unknown

CVE-2008-1969

Disclosure Date: April 27, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Cezanne 6.5.1 and 7 allow remote attackers to inject arbitrary web script or HTML via the (1) LookUPId and (2) CbFun parameters to (a) CFLookUP.asp; (3) TitleParms, (4) WidgetsHeights, (5) WidgetsLinks, and (6) WidgetsTitles parameters to (b) CznCommon/CznCustomContainer.asp, (7) CFTARGET parameter to (c) home.asp, (8) PersonOid parameter to (d) PeopleWeb/Cards/CVCard.asp, (9) DESTLINKOID and PersonOID parameters to (e) PeopleWeb/Cards/PayrollCard.asp, and the (10) FolderTemplateId and (11) FolderTemplateName parameters to (f) PeopleWeb/CznDocFolder/CznDFStartProcess.asp.
0
Attacker Value
Unknown

CVE-2008-1968

Disclosure Date: April 27, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Cezanne 7 allow remote authenticated users to execute arbitrary SQL commands via the FUNID parameter to (1) CFLookup.asp and (2) CznCommon/CznCustomContainer.asp.
0
Attacker Value
Unknown

CVE-2008-1967

Disclosure Date: April 27, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in CFLogon/CFLogon.asp in Cezanne 6.5.1 and 7 allows remote attackers to inject arbitrary web script or HTML via the SleUserName parameter.
0
Attacker Value
Unknown

CVE-2008-1629

Disclosure Date: April 02, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in PHPkrm before 1.5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0