Show filters
548 Total Results
Displaying 471-480 of 548
Sort by:
Attacker Value
Unknown

CVE-2008-1426

Disclosure Date: March 20, 2008 (last updated October 04, 2023)
SQL injection vulnerability in album.asp in KAPhotoservice allows remote attackers to execute arbitrary SQL commands via the albumid parameter.
0
Attacker Value
Unknown

CVE-2008-0819

Disclosure Date: February 19, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in PlutoStatus Locator 1.0 pre alpha allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.
0
Attacker Value
Unknown

CVE-2008-0149

Disclosure Date: January 09, 2008 (last updated October 04, 2023)
TUTOS 1.3 allows remote attackers to read system information via a direct request to php/admin/phpinfo.php, which calls the phpinfo function.
0
Attacker Value
Unknown

CVE-2008-0148

Disclosure Date: January 09, 2008 (last updated October 04, 2023)
TUTOS 1.3 does not restrict access to php/admin/cmd.php, which allows remote attackers to execute arbitrary shell commands via the cmd parameter in a direct request.
0
Attacker Value
Unknown

CVE-2007-6283

Disclosure Date: December 18, 2007 (last updated October 04, 2023)
Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as causing a denial of service by stopping named.
0
Attacker Value
Unknown

CVE-2007-5651

Disclosure Date: October 23, 2007 (last updated October 04, 2023)
Unspecified vulnerability in the Extensible Authentication Protocol (EAP) implementation in Cisco IOS 12.3 and 12.4 on Cisco Access Points and 1310 Wireless Bridges (Wireless EAP devices), IOS 12.1 and 12.2 on Cisco switches (Wired EAP devices), and CatOS 6.x through 8.x on Cisco switches allows remote attackers to cause a denial of service (device reload) via a crafted EAP Response Identity packet.
0
Attacker Value
Unknown

CVE-2007-5157

Disclosure Date: October 01, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in phfito-post.php in Alex Kocharin PHP Fidonet Tosser (PhFiTo) 1.3.0 in phpFidoNode allows remote attackers to execute arbitrary PHP code via a URL in the SRC_PATH parameter to phfito-post.
0
Attacker Value
Unknown

CVE-2007-5134

Disclosure Date: September 27, 2007 (last updated October 04, 2023)
Cisco Catalyst 6500 and Cisco 7600 series devices use 127/8 IP addresses for Ethernet Out-of-Band Channel (EOBC) internal communication, which might allow remote attackers to send packets to an interface for which network exposure was unintended.
0
Attacker Value
Unknown

CVE-2007-3711

Disclosure Date: July 11, 2007 (last updated October 04, 2023)
Unspecified vulnerability in TOS 2.1.x, 2.2.x before 2.2.5, and 2.5.x before 2.5.2 on TippingPoint IPS allows remote attackers to avoid detection by sending certain fragmented packets.
0
Attacker Value
Unknown

CVE-2007-3701

Disclosure Date: July 11, 2007 (last updated October 04, 2023)
TippingPoint IPS before 20070710 does not properly handle a hex-encoded alternate Unicode '/' (slash) character, which might allow remote attackers to send certain network traffic and avoid detection, as demonstrated by a cmd.exe attack.
0