Show filters
72 Total Results
Displaying 51-60 of 72
Sort by:
Attacker Value
Unknown

CVE-2014-7696

Disclosure Date: October 21, 2014 (last updated October 05, 2023)
The Halftime Magazine (aka com.magzter.halftimemagazine) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-6731

Disclosure Date: September 26, 2014 (last updated October 05, 2023)
The Alfa-Bank (aka ru.alfabank.mobile.android) application 5.5.1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-2939

Disclosure Date: June 02, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Alfresco Enterprise before 4.1.6.13 allow remote attackers to inject arbitrary web script or HTML via (1) an XHTML document, (2) a <% tag, or (3) the taskId parameter to share/page/task-edit.
0
Attacker Value
Unknown

CVE-2012-0315

Disclosure Date: February 22, 2012 (last updated October 04, 2023)
Untrusted search path vulnerability in ALFTP before 5.31 allows local users to gain privileges via a Trojan horse executable file in a directory that is accessed for reading an extensionless file, as demonstrated by executing the README.exe file when a user attempts to access the README file.
0
Attacker Value
Unknown

CVE-2009-4451

Disclosure Date: December 29, 2009 (last updated October 04, 2023)
Unrestricted file upload vulnerability in upper.php in kandalf upper 0.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in fileup/.
0
Attacker Value
Unknown

CVE-2008-2702

Disclosure Date: June 13, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in the FTP client in ALTools ESTsoft ALFTP 4.1 beta 2 and 5.0 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345. NOTE: this can be leveraged for code execution by writing to a Startup folder.
0
Attacker Value
Unknown

CVE-2007-5713

Disclosure Date: October 30, 2007 (last updated October 04, 2023)
Off-by-one error in the GeoIP module in the AMX Mod X 1.76d plugin for Half-Life Server might allow attackers to execute arbitrary code or cause a denial of service via unspecified input related to geolocation, which triggers an error message from the (1) geoip_code2 or (2) geoip_code3 function, leading to a buffer overflow.
0
Attacker Value
Unknown

CVE-2007-5477

Disclosure Date: October 16, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in auth.w in djeyl.net WebMod 0.48 Half-Life Dedicated Server plugin allows remote attackers to inject arbitrary web script or HTML via the redir parameter.
0
Attacker Value
Unknown

CVE-2007-4127

Disclosure Date: August 01, 2007 (last updated November 08, 2023)
PHP remote file inclusion vulnerability in check_entry.php in Ralf Image Gallery (RIG), aka Raphael Moll RIG Image Gallery, 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the dir_abs_src parameter. NOTE: this issue is disputed by multiple third parties, who report that the product exits if register_globals is enabled, thereby blocking exploitation. NOTE: CVE-2006-3210.a covers this issue in versions before 1.0
0
Attacker Value
Unknown

CVE-2006-5949

Disclosure Date: November 17, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in ALTools ALFTP FTP Server 4.1 beta 1, and possibly earlier, allows remote attackers to create arbitrary directories via directory traversal sequences in a MKD request. NOTE: the provenance of this information is unknown; details are obtained from third party sources.
0