Show filters
545 Total Results
Displaying 451-460 of 545
Sort by:
Attacker Value
Unknown

CVE-2008-0562

Disclosure Date: February 04, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the Restaurant (com_restaurant) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.
0
Attacker Value
Unknown

CVE-2008-0338

Disclosure Date: January 17, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in the mwGetLocalFileName function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to read arbitrary files and list arbitrary directories via a (1) .%2e (partially encoded dot dot) or (2) %2e%2e (encoded dot dot) in the URI.
0
Attacker Value
Unknown

CVE-2008-0337

Disclosure Date: January 17, 2008 (last updated October 04, 2023)
Heap-based buffer overflow in the _mwProcessReadSocket function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to execute arbitrary code via a long URI.
0
Attacker Value
Unknown

CVE-2007-6459

Disclosure Date: December 20, 2007 (last updated October 04, 2023)
Anon Proxy Server 0.100, and probably 0.101, allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the host parameter to diagdns.php, and (2) the host parameter and possibly (3) the port parameter to diagconnect.php, a different vulnerability than CVE-2007-6460.
0
Attacker Value
Unknown

CVE-2007-6460

Disclosure Date: December 20, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Anon Proxy Server before 0.101 allow remote attackers to inject arbitrary web script or HTML via the URI, which is later displayed by (1) log.php or (2) logerror.php, a different vulnerability than CVE-2007-6459.
0
Attacker Value
Unknown

CVE-2007-6453

Disclosure Date: December 20, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in raidenhttpd-admin/workspace.php in RaidenHTTPD 2.0.19, when the WebAdmin function is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ulang parameter.
0
Attacker Value
Unknown

CVE-2007-5685

Disclosure Date: October 28, 2007 (last updated October 04, 2023)
The safe_path function in shttp before 0.0.5 allows remote attackers to conduct directory traversal attacks and read files via a combination of ".." and sub-directory specifiers that resolve to a pathname that is at or below the same level as the web document root, but in a different part of the directory tree.
0
Attacker Value
Unknown

CVE-2007-4505

Disclosure Date: August 23, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the RemoSitory component (com_remository) for Mambo allows remote attackers to execute arbitrary SQL commands via the cat parameter in a selectcat action.
0
Attacker Value
Unknown

CVE-2007-3710

Disclosure Date: July 11, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in example/gamedemo/inc.functions.php in PHP Comet-Server allows remote attackers to execute arbitrary PHP code via a URL in the projectPath parameter.
0
Attacker Value
Unknown

CVE-2007-3365

Disclosure Date: June 22, 2007 (last updated February 08, 2024)
MyServer 0.8.9 and earlier does not properly handle uppercase characters in filename extensions, which allows remote attackers to obtain sensitive information (script source code) via a modified extension, as demonstrated by post.mscgI.