Show filters
535 Total Results
Displaying 471-480 of 535
Sort by:
Attacker Value
Unknown
CVE-2007-0259
Disclosure Date: January 16, 2007 (last updated October 04, 2023)
Ezboxx Portal System Beta 0.7.6 and earlier allows remote attackers to obtain sensitive information via an invalid cat parameter to boxx/knowledgebase.asp, which reveals the path in an error message.
0
Attacker Value
Unknown
CVE-2007-0265
Disclosure Date: January 16, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Ezboxx Portal System Beta 0.7.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the pic parameter to custom/piczoom.asp, (2) the nocatname parameter to boxx/user-upload.asp, or (3) the iid parameter to indexes/newscomments.asp.
0
Attacker Value
Unknown
CVE-2007-0266
Disclosure Date: January 16, 2007 (last updated October 04, 2023)
SQL injection vulnerability in boxx/ShowAppendix.asp in Ezboxx Portal System Beta 0.7.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the iid parameter.
0
Attacker Value
Unknown
CVE-2006-6899
Disclosure Date: December 31, 2006 (last updated October 04, 2023)
hidd in BlueZ (bluez-utils) before 2.25 allows remote attackers to obtain control of the (1) Mouse and (2) Keyboard Human Interface Device (HID) via a certain configuration of two HID (PSM) endpoints, operating as a server, aka HidAttack.
0
Attacker Value
Unknown
CVE-2006-6793
Disclosure Date: December 28, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in ataturk.php in Okul Merkezi Portal 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
0
Attacker Value
Unknown
CVE-2006-6771
Disclosure Date: December 27, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Irokez CMS 0.7.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[PTH][func] parameter in (a) scripts/gallery.scr.php; the (2) GLOBALS[PTH][spaw] parameter in (b) scripts/xtextarea.scr.php; and the (3) GLOBALS[PTH][classes] parameter in (c) sitemap.scr.php, (d) news.scr.php, (e) polls.scr.php, (f) rss.scr.php, (g) search.scr.php in scripts/, and (h) form.fun.php, (i) general.func.php, (j) groups.func.php, (k) js.func.php, (l) sections.func.php, and (m) users.func.php in functions/.
0
Attacker Value
Unknown
CVE-2006-6564
Disclosure Date: December 15, 2006 (last updated October 04, 2023)
FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a malformed argument to the STOR command, which results in a NULL pointer dereference. NOTE: CVE analysis suggests that the problem might be due to a malformed PORT command.
0
Attacker Value
Unknown
CVE-2006-6565
Disclosure Date: December 15, 2006 (last updated October 04, 2023)
FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to the (1) LIST or (2) NLST commands, which results in a NULL pointer dereference, a different set of vectors than CVE-2006-6564. NOTE: CVE analysis suggests that the problem might be due to a malformed PORT command.
0
Attacker Value
Unknown
CVE-2006-6524
Disclosure Date: December 14, 2006 (last updated October 04, 2023)
SQL injection vulnerability in vdateUsr.asp in EzHRS HR Assist 1.05 and earlier allows remote attackers to execute arbitrary SQL commands via the Uname (UserName) parameter.
0
Attacker Value
Unknown
CVE-2006-6525
Disclosure Date: December 14, 2006 (last updated October 04, 2023)
SQL injection vulnerability in vdateUsr.asp in EzHRS HR Assist 1.05 and earlier allows remote attackers to execute arbitrary SQL commands via the password parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
0