Show filters
534 Total Results
Displaying 461-470 of 534
Sort by:
Attacker Value
Unknown
CVE-2007-0952
Disclosure Date: February 15, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Scriptsez.net Virtual Calendar allow remote attackers to inject arbitrary web script or HTML via the (1) t and (2) yr parameters, and the (3) sho parameter when the m parameter is outside the intended range.
0
Attacker Value
Unknown
CVE-2007-0580
Disclosure Date: January 30, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in menu.php in Foro Domus 2.10 allows remote attackers to execute arbitrary PHP code via a URL in the sesion_idioma parameter.
0
Attacker Value
Unknown
CVE-2007-0518
Disclosure Date: January 26, 2007 (last updated October 04, 2023)
Scriptsez Smart PHP Subscriber (aka subscribe) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain encoded passwords via a direct request for pwd.txt.
0
Attacker Value
Unknown
CVE-2007-0517
Disclosure Date: January 26, 2007 (last updated October 04, 2023)
Scriptsez Random PHP Quote 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password information via a direct request for pwd.txt.
0
Attacker Value
Unknown
CVE-2007-0317
Disclosure Date: January 18, 2007 (last updated October 04, 2023)
Format string vulnerability in the LogMessage function in FileZilla before 3.0.0-beta5 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted arguments. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2007-0315
Disclosure Date: January 18, 2007 (last updated October 04, 2023)
Multiple buffer overflows in FileZilla before 2.2.30a allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors related to (1) Options.cpp when storing settings in the registry, and (2) the transfer queue (QueueCtrl.cpp). NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2007-0259
Disclosure Date: January 16, 2007 (last updated October 04, 2023)
Ezboxx Portal System Beta 0.7.6 and earlier allows remote attackers to obtain sensitive information via an invalid cat parameter to boxx/knowledgebase.asp, which reveals the path in an error message.
0
Attacker Value
Unknown
CVE-2007-0265
Disclosure Date: January 16, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Ezboxx Portal System Beta 0.7.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the pic parameter to custom/piczoom.asp, (2) the nocatname parameter to boxx/user-upload.asp, or (3) the iid parameter to indexes/newscomments.asp.
0
Attacker Value
Unknown
CVE-2007-0266
Disclosure Date: January 16, 2007 (last updated October 04, 2023)
SQL injection vulnerability in boxx/ShowAppendix.asp in Ezboxx Portal System Beta 0.7.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the iid parameter.
0
Attacker Value
Unknown
CVE-2006-6899
Disclosure Date: December 31, 2006 (last updated October 04, 2023)
hidd in BlueZ (bluez-utils) before 2.25 allows remote attackers to obtain control of the (1) Mouse and (2) Keyboard Human Interface Device (HID) via a certain configuration of two HID (PSM) endpoints, operating as a server, aka HidAttack.
0