Show filters
74 Total Results
Displaying 51-60 of 74
Sort by:
Attacker Value
Unknown
CVE-2016-10072
Disclosure Date: December 27, 2016 (last updated November 08, 2023)
WampServer 3.0.6 has two files called 'wampmanager.exe' and 'unins000.exe' with a weak ACL for Modify. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system. To properly exploit this vulnerability, the local attacker must insert an executable file called wampmanager.exe or unins000.exe and replace the original files. The next time one of these programs is launched by a more privileged user, malicious code chosen by the local attacker will run. NOTE: the vendor disputes the relevance of this report, taking the position that a configuration in which "'someone' (an attacker) is able to replace files on a PC" is not "the fault of WampServer.
0
Attacker Value
Unknown
CVE-2016-10031
Disclosure Date: December 27, 2016 (last updated November 08, 2023)
WampServer 3.0.6 installs two services called 'wampapache' and 'wampmysqld' with weak file permissions, running with SYSTEM privileges. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system. To properly exploit this vulnerability, the local attacker must insert an executable file called mysqld.exe or httpd.exe and replace the original files. The next time the service starts, the malicious file will get executed as SYSTEM. NOTE: the vendor disputes the relevance of this report, taking the position that a configuration in which "'someone' (an attacker) is able to replace files on a PC" is not "the fault of WampServer.
0
Attacker Value
Unknown
CVE-2014-8390
Disclosure Date: April 03, 2015 (last updated October 05, 2023)
Multiple buffer overflows in Schneider Electric VAMPSET before 2.2.168 allow local users to gain privileges via malformed disturbance-recording data in a (1) CFG or (2) DAT file.
0
Attacker Value
Unknown
CVE-2014-7726
Disclosure Date: October 21, 2014 (last updated October 05, 2023)
The Golosinas Simpson1 (aka com.wGolosinasSimpson1) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-5407
Disclosure Date: September 15, 2014 (last updated October 05, 2023)
Multiple stack-based buffer overflows in Schneider Electric VAMPSET 2.2.136 and earlier allow local users to cause a denial of service (application halt) via a malformed (1) setting file or (2) disturbance recording file.
0
Attacker Value
Unknown
CVE-2012-5224
Disclosure Date: October 01, 2012 (last updated October 05, 2023)
PHP remote file inclusion vulnerability in vb/includes/vba_cmps_include_bottom.php in vBadvanced CMPS 3.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pages[template] parameter.
0
Attacker Value
Unknown
CVE-2012-1795
Disclosure Date: March 20, 2012 (last updated October 04, 2023)
webglimpse.cgi in Webglimpse before 2.20.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the query parameter, as exploited in the wild in March 2012.
0
Attacker Value
Unknown
CVE-2009-5114
Disclosure Date: March 19, 2012 (last updated October 04, 2023)
Directory traversal vulnerability in wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the DOC parameter.
0
Attacker Value
Unknown
CVE-2012-1787
Disclosure Date: March 19, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in wgarcmin.cgi in Webglimpse 2.20.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) URL, (2) FILE, or (3) DOMAIN parameters.
0
Attacker Value
Unknown
CVE-2009-5112
Disclosure Date: March 19, 2012 (last updated October 04, 2023)
wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to obtain the installation path via a crafted request.
0