Show filters
62 Total Results
Displaying 51-60 of 62
Sort by:
Attacker Value
Unknown
CVE-2013-5655
Disclosure Date: May 14, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in the FTP server in YingZhi Python Programming Language for iOS 1.9 allows remote attackers to read and possibly write arbitrary files via a .. (dot dot) in the default URI.
0
Attacker Value
Unknown
CVE-2013-1066
Disclosure Date: October 03, 2013 (last updated October 05, 2023)
language-selector 0.110.x before 0.110.1, 0.90.x before 0.90.1, and 0.79.x before 0.79.4 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
0
Attacker Value
Unknown
CVE-2012-2065
Disclosure Date: September 05, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Language Icons module 6.x-2.x before 6.x-2.1 and 7.x-1.x before 7.x-1.0 for Drupal allows remote authenticated users with administer languages permissions to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2011-1842
Disclosure Date: May 03, 2011 (last updated October 04, 2023)
dbus_backend/lsd.py in the D-Bus backend in language-selector before 0.6.7 does not validate the arguments to the (1) SetSystemDefaultLangEnv and (2) SetSystemDefaultLanguageEnv functions, which allows local users to gain privileges via shell metacharacters in a string argument, a different vulnerability than CVE-2011-0729.
0
Attacker Value
Unknown
CVE-2011-0729
Disclosure Date: April 29, 2011 (last updated October 04, 2023)
dbus_backend/ls-dbus-backend in the D-Bus backend in language-selector before 0.6.7 does not restrict access on the basis of a PolicyKit check result, which allows local users to modify the /etc/default/locale and /etc/environment files via a (1) SetSystemDefaultLangEnv or (2) SetSystemDefaultLanguageEnv call.
0
Attacker Value
Unknown
CVE-2008-6267
Disclosure Date: February 25, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in detail.php in Multi Languages WebShop Online 1.02 allows remote attackers to inject arbitrary web script or HTML via the name parameter.
0
Attacker Value
Unknown
CVE-2008-6268
Disclosure Date: February 25, 2009 (last updated October 04, 2023)
SQL injection vulnerability in detail.php in WEBBDOMAIN Multi Languages WebShop Online 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown
CVE-2008-0666
Disclosure Date: February 11, 2008 (last updated October 04, 2023)
Website META Language (WML) 2.0.11 allows local users to overwrite arbitrary files via a symlink attack on (1) the /tmp/pe.tmp.$$ temporary file used by wml_contrib/wmg.cgi and (2) temporary files used by wml_backend/p3_eperl/eperl_sys.c.
0
Attacker Value
Unknown
CVE-2008-0665
Disclosure Date: February 11, 2008 (last updated October 04, 2023)
wml_backend/p1_ipp/ipp.src in Website META Language (WML) 2.0.11 allows local users to overwrite arbitrary files via a symlink attack on the ipp.$$.tmp temporary file.
0
Attacker Value
Unknown
CVE-2007-1939
Disclosure Date: April 10, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the embedded webserver in Daniel Naber LanguageTool before 0.8.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving an error message, possibly the demultiplex method in HTTPServer.java.
0