Show filters
530 Total Results
Displaying 451-460 of 530
Sort by:
Attacker Value
Unknown

CVE-2006-7218

Disclosure Date: July 06, 2007 (last updated October 04, 2023)
eZ publish before 3.8.1 does not properly enforce permissions for "content edit Language" when there are four or more languages, which allows remote authenticated users to perform translations into languages that are not listed in a Module Function Limitation policy.
0
Attacker Value
Unknown

CVE-2007-2888

Disclosure Date: May 30, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in UltraISO 8.6.2.2011 and earlier allows user-assisted remote attackers to execute arbitrary code via a long FILE string (filename) in a .cue file, a related issue to CVE-2007-2761. NOTE: some details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2007-2318

Disclosure Date: April 26, 2007 (last updated October 04, 2023)
Multiple format string vulnerabilities in FileZilla before 2.2.32 allow remote attackers to execute arbitrary code via format string specifiers in (1) FTP server responses or (2) data sent by an FTP server. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2007-2156

Disclosure Date: April 19, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Rezervi Generic 0.9 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) datumVonDatumBis.inc.php, (2) footer.inc.php, (3) header.inc.php, and (4) stylesheets.php in templates/; and (5) wochenuebersicht.inc.php, (6) monatsuebersicht.inc.php, (7) jahresuebersicht.inc.php, and (8) tagesuebersicht.inc.php in belegungsplan/.
0
Attacker Value
Unknown

CVE-2006-7103

Disclosure Date: March 03, 2007 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in EZOnlineGallery 1.3 and earlier, and possibly other versions before 1.3.2 Beta, allow remote attackers to (1) determine directory existence via a ".." in the album parameter in a show_album action to (a) ezgallery.php, which produces different responses depending on existence; and read arbitrary image files via a ".." in the album or (2) image parameter to (b) image.php.
0
Attacker Value
Unknown

CVE-2006-7059

Disclosure Date: February 24, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Scriptsez.net E-Dating System allow remote attackers to inject arbitrary web script or HTML via encoded entities (&#0000039) in IMG tags to (1) messages, (2) profile fields, or (3) the id parameter in a dologin operation to cindex.php.
0
Attacker Value
Unknown

CVE-2006-7060

Disclosure Date: February 24, 2007 (last updated October 04, 2023)
cindex.php in Scriptsez.net E-Dating System allows remote attackers to obtain the full path via an invalid id parameter in a dologin action, which leaks the path in an error message.
0
Attacker Value
Unknown

CVE-2006-7061

Disclosure Date: February 24, 2007 (last updated October 04, 2023)
Scriptsez.net E-Dating System stores data files with predictable names under the web document root with insufficient access control, which allows remote attackers to read private messages and leverage them for cross-site scripting (XSS) attacks.
0
Attacker Value
Unknown

CVE-2007-1043

Disclosure Date: February 21, 2007 (last updated October 04, 2023)
Ezboo webstats, possibly 3.0.3, allows remote attackers to bypass authentication and gain access via a direct request to (1) update.php and (2) config.php.
0
Attacker Value
Unknown

CVE-2007-0974

Disclosure Date: February 16, 2007 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in Ian Bezanson DropBox before 0.0.4 beta have unknown impact and attack vectors, possibly related to a variable extraction vulnerability.
0