Show filters
64 Total Results
Displaying 51-60 of 64
Sort by:
Attacker Value
Unknown
CVE-2014-1466
Disclosure Date: January 15, 2014 (last updated October 05, 2023)
SQL injection vulnerability in CSP MySQL User Manager 2.3 allows remote attackers to execute arbitrary SQL commands via the login field of the login page.
0
Attacker Value
Unknown
CVE-2013-1933
Disclosure Date: April 25, 2013 (last updated October 05, 2023)
The extract_from_ocr function in lib/docsplit/text_extractor.rb in the Karteek Docsplit (karteek-docsplit) gem 0.5.4 for Ruby allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a PDF filename.
0
Attacker Value
Unknown
CVE-2008-6165
Disclosure Date: February 19, 2009 (last updated October 04, 2023)
SQL injection vulnerability in gestion.php in CSPartner 0.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the (1) pseudo and (2) passe parameters.
0
Attacker Value
Unknown
CVE-2008-4191
Disclosure Date: September 24, 2008 (last updated October 04, 2023)
extract-table.pl in Emacspeak 26 and 28 allows local users to overwrite arbitrary files via a symlink attack on the extract-table.csv temporary file.
0
Attacker Value
Unknown
CVE-2008-3448
Disclosure Date: August 04, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in common solutions csphonebook 1.02 allows remote attackers to inject arbitrary web script or HTML via the letter parameter.
0
Attacker Value
Unknown
CVE-2006-4088
Disclosure Date: August 11, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in CivicSpace 0.8.5 allow remote attackers to inject arbitrary web script or HTML via the (1) Subject, (2) Comment, and (3) Add new comment sections.
0
Attacker Value
Unknown
CVE-2006-1115
Disclosure Date: March 09, 2006 (last updated February 22, 2025)
nCipher HSM before 2.22.6, when generating a Diffie-Hellman public/private key pair without any specified DiscreteLogGroup parameters, chooses random parameters that could allow an attacker to crack the private key in significantly less time than a brute force attack.
0
Attacker Value
Unknown
CVE-2002-0920
Disclosure Date: October 04, 2002 (last updated February 22, 2025)
CGIScript.net csPassword.cgi stores usernames and unencrypted passwords in the password.cgi.tmp temporary file while modifying data, which could allow local users (and possibly remote attackers) to gain privileges by stealing the file before it has been processed.
0
Attacker Value
Unknown
CVE-2002-0919
Disclosure Date: October 04, 2002 (last updated February 22, 2025)
CGIScript.net csPassword.cgi allows remote authenticated users to modify the .htaccess file and gain privileges via newlines in the title field of the edit page.
0
Attacker Value
Unknown
CVE-2002-0940
Disclosure Date: October 04, 2002 (last updated February 22, 2025)
domesticinstall.exe for nCipher MSCAPI CSP 5.50 and 5.54 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lower protection level than specified by the user (module protection only).
0