Show filters
530 Total Results
Displaying 441-450 of 530
Sort by:
Attacker Value
Unknown

CVE-2008-0767

Disclosure Date: February 13, 2008 (last updated October 04, 2023)
ExtremeZ-IP.exe in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier does not verify that a certain "number of URLs" field is consistent with the packet length, which allows remote attackers to cause a denial of service (daemon crash) via a large integer in this field in a packet to the Service Location Protocol (SLP) service on UDP port 427, triggering an out-of-bounds read.
0
Attacker Value
Unknown

CVE-2008-0133

Disclosure Date: January 08, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Tribisur 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to cat_main.php and the (2) cat parameter to forum.php in a liste action.
0
Attacker Value
Unknown

CVE-2007-6368

Disclosure Date: December 15, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in ezContents 1.4.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the link parameter.
0
Attacker Value
Unknown

CVE-2007-4493

Disclosure Date: August 23, 2007 (last updated October 04, 2023)
eZ publish before 3.8.9, and 3.9 before 3.9.3, does not properly check permissions on module views that lack a policy function, which has unknown impact and attack vectors, as demonstrated by a vulnerability in the discount functionality in the shop module.
0
Attacker Value
Unknown

CVE-2007-4494

Disclosure Date: August 23, 2007 (last updated October 04, 2023)
The tipafriend function in eZ publish before 3.8.9, and 3.9 before 3.9.3, does not limit access by anonymous users, which allows remote attackers to conduct spam attacks.
0
Attacker Value
Unknown

CVE-2007-4259

Disclosure Date: August 08, 2007 (last updated October 04, 2023)
EZPhotoSales 1.9.3 and earlier allows remote attackers to download arbitrary image files via (1) a direct request for a URL under OnlineViewing/galleries/ or (2) navigation of the gallery user interface with JavaScript disabled.
0
Attacker Value
Unknown

CVE-2007-4261

Disclosure Date: August 08, 2007 (last updated October 04, 2023)
EZPhotoSales 1.9.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download (1) a file containing cleartext passwords via a direct request for OnlineViewing/data/galleries.txt, or (2) a file containing username hashes and password hashes via a direct request for OnlineViewing/configuration/config.dat/. NOTE: vector 2 can be leveraged for administrative access because authentication does not require knowledge of cleartext values, but instead uses the username hash in the ConfigLogin parameter and the password hash in the ConfigPassword parameter.
0
Attacker Value
Unknown

CVE-2007-4262

Disclosure Date: August 08, 2007 (last updated October 04, 2023)
Unrestricted file upload vulnerability in EZPhotoSales 1.9.3 and earlier allows remote authenticated administrators to upload and execute arbitrary PHP code under OnlineViewing/galleries/.
0
Attacker Value
Unknown

CVE-2007-4260

Disclosure Date: August 08, 2007 (last updated October 04, 2023)
EZPhotoSales 1.9.3 and earlier has a default "admin" account for galleries, which allows remote attackers to access arbitrary galleries by specifying this username.
0
Attacker Value
Unknown

CVE-2006-7218

Disclosure Date: July 06, 2007 (last updated October 04, 2023)
eZ publish before 3.8.1 does not properly enforce permissions for "content edit Language" when there are four or more languages, which allows remote authenticated users to perform translations into languages that are not listed in a Module Function Limitation policy.
0