Show filters
61 Total Results
Displaying 51-60 of 61
Sort by:
Attacker Value
Unknown

CVE-2006-2503

Disclosure Date: May 22, 2006 (last updated October 04, 2023)
SQL injection vulnerability in misc.php in DeluxeBB 1.06 allows remote attackers to execute arbitrary SQL commands via the name parameter.
0
Attacker Value
Unknown

CVE-2006-1119

Disclosure Date: March 09, 2006 (last updated February 22, 2025)
fantastico in Cpanel does not properly handle when it has insufficient permissions to perform certain file operations, which allows remote authenticated users to obtain the full pathname, which is leaked in a PHP error message.
0
Attacker Value
Unknown

CVE-2006-1108

Disclosure Date: March 09, 2006 (last updated February 22, 2025)
SQL injection vulnerability in news.php in NMDeluxe before 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2006-1107

Disclosure Date: March 09, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in news.php in NMDeluxe before 1.0.1 allows remote attackers to inject arbitrary web script or HTML via the nick parameter.
0
Attacker Value
Unknown

CVE-2006-0926

Disclosure Date: February 28, 2006 (last updated February 22, 2025)
Multiple directory traversal vulnerabilities in Allume StuffIt Standard and Deluxe 9.0, ZipMagic Deluxe 9.0, and StuffIt Expander 9.0.0.21 Engine 9.0.0.21 allow remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a (1) zip or (2) tar archive.
0
Attacker Value
Unknown

CVE-2005-2989

Disclosure Date: September 20, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in DeluxeBB 1.0 and 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) tid parameter to topic.php, the uid parameter to (2) misc.php or (3) pm.php, or the fid parameter to (3) forums.php or (4) newpost.php.
0
Attacker Value
Unknown

CVE-2005-2259

Disclosure Date: July 13, 2005 (last updated February 22, 2025)
The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANet Shopping Mall Software, (2) Domain Name Auction Software, (3) Standard Classified Ads Software, and (4) MakeBid Reverse Auction allows remote attackers to execute arbitrary code via shell metacharacters in the DISPCLOSED parameter.
0
Attacker Value
Unknown

CVE-2005-1092

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Lightspeed DeluxeFTP 6.01 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local users to gain privileges.
0
Attacker Value
Unknown

CVE-2004-2398

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Netenberg Fantastico De Luxe 2.8 uses database file names that contain the associated usernames, which allows local users to determine valid usernames and conduct brute force attacks by reading the file names from /var/lib/mysql, which is assigned world-readable permissions by cPanel 9.3.0 R5.
0
Attacker Value
Unknown

CVE-2002-0257

Disclosure Date: May 29, 2002 (last updated February 22, 2025)
Cross-site scripting vulnerability in auction.pl of MakeBid Auction Deluxe 3.30 allows remote attackers to obtain information from other users via the form fields (1) TITLE, (2) DESCTIT, (3) DESC, (4) searchstring, (5) ALIAS, (6) EMAIL, (7) ADDRESS1, (8) ADDRESS2, (9) ADDRESS3, (10) PHONE1, (11) PHONE2, (12) PHONE3, or (13) PHONE4.
0