Show filters
530 Total Results
Displaying 451-460 of 530
Sort by:
Attacker Value
Unknown
CVE-2006-7218
Disclosure Date: July 06, 2007 (last updated October 04, 2023)
eZ publish before 3.8.1 does not properly enforce permissions for "content edit Language" when there are four or more languages, which allows remote authenticated users to perform translations into languages that are not listed in a Module Function Limitation policy.
0
Attacker Value
Unknown
CVE-2007-2888
Disclosure Date: May 30, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in UltraISO 8.6.2.2011 and earlier allows user-assisted remote attackers to execute arbitrary code via a long FILE string (filename) in a .cue file, a related issue to CVE-2007-2761. NOTE: some details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2007-2318
Disclosure Date: April 26, 2007 (last updated October 04, 2023)
Multiple format string vulnerabilities in FileZilla before 2.2.32 allow remote attackers to execute arbitrary code via format string specifiers in (1) FTP server responses or (2) data sent by an FTP server. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2007-2156
Disclosure Date: April 19, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Rezervi Generic 0.9 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) datumVonDatumBis.inc.php, (2) footer.inc.php, (3) header.inc.php, and (4) stylesheets.php in templates/; and (5) wochenuebersicht.inc.php, (6) monatsuebersicht.inc.php, (7) jahresuebersicht.inc.php, and (8) tagesuebersicht.inc.php in belegungsplan/.
0
Attacker Value
Unknown
CVE-2006-7103
Disclosure Date: March 03, 2007 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in EZOnlineGallery 1.3 and earlier, and possibly other versions before 1.3.2 Beta, allow remote attackers to (1) determine directory existence via a ".." in the album parameter in a show_album action to (a) ezgallery.php, which produces different responses depending on existence; and read arbitrary image files via a ".." in the album or (2) image parameter to (b) image.php.
0
Attacker Value
Unknown
CVE-2006-7059
Disclosure Date: February 24, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Scriptsez.net E-Dating System allow remote attackers to inject arbitrary web script or HTML via encoded entities (') in IMG tags to (1) messages, (2) profile fields, or (3) the id parameter in a dologin operation to cindex.php.
0
Attacker Value
Unknown
CVE-2006-7060
Disclosure Date: February 24, 2007 (last updated October 04, 2023)
cindex.php in Scriptsez.net E-Dating System allows remote attackers to obtain the full path via an invalid id parameter in a dologin action, which leaks the path in an error message.
0
Attacker Value
Unknown
CVE-2006-7061
Disclosure Date: February 24, 2007 (last updated October 04, 2023)
Scriptsez.net E-Dating System stores data files with predictable names under the web document root with insufficient access control, which allows remote attackers to read private messages and leverage them for cross-site scripting (XSS) attacks.
0
Attacker Value
Unknown
CVE-2007-1043
Disclosure Date: February 21, 2007 (last updated October 04, 2023)
Ezboo webstats, possibly 3.0.3, allows remote attackers to bypass authentication and gain access via a direct request to (1) update.php and (2) config.php.
0
Attacker Value
Unknown
CVE-2007-0974
Disclosure Date: February 16, 2007 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in Ian Bezanson DropBox before 0.0.4 beta have unknown impact and attack vectors, possibly related to a variable extraction vulnerability.
0