Show filters
92 Total Results
Displaying 51-60 of 92
Sort by:
Attacker Value
Unknown
CVE-2008-3539
Disclosure Date: September 11, 2008 (last updated October 04, 2023)
Unspecified vulnerability in HP OpenView Select Identity (HPSI) Connectors on Windows, as used in HPSI Active Directory Connector 2.30 and earlier, HPSI SunOne Connector 1.14 and earlier, HPSI eDirectory Connector 1.12 and earlier, HPSI eTrust Connector 1.02 and earlier, HPSI OID Connector 1.02 and earlier, HPSI IBM Tivoli Dir Connector 1.02 and earlier, HPSI TOPSecret Connector 2.22.001 and earlier, HPSI RACF Connector 1.12.001 and earlier, HPSI ACF2 Connector 1.02 and earlier, HPSI OpenLDAP Connector 1.02 and earlier, and HPSI BiDir DirX Connector 1.00.003 and earlier, allows local users to obtain sensitive information via unknown vectors.
0
Attacker Value
Unknown
CVE-2008-3598
Disclosure Date: August 12, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in psipuss 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the Cid parameter to categories.php or (2) the Username parameter to login.php.
0
Attacker Value
Unknown
CVE-2008-1665
Disclosure Date: July 17, 2008 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in HP Select Identity (HPSI) Active Directory Bidirectional LDAP Connector 2.20, 2.20.001, 2.20.002, and 2.30 allow remote attackers to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-1784
Disclosure Date: April 15, 2008 (last updated October 04, 2023)
Prozilla Topsites 1.0 allows remote attackers to perform administrative actions via a direct request to (1) addu.php, (2) editu.php, and (3) uidx.php in siteadmin/.
0
Attacker Value
Unknown
CVE-2007-5918
Disclosure Date: November 10, 2007 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in edit.php in the MS TopSites add-on for PHP-Nuke does not verify that the uname parameter matches the current account, which allows remote authenticated users to change arbitrary accounts or change the SiteTitleName field as an arbitrary user via a modified uname value in an edit action to modules.php.
0
Attacker Value
Unknown
CVE-2007-4881
Disclosure Date: September 14, 2007 (last updated October 04, 2023)
SQL injection vulnerability in profile/myprofile.php in psi-labs.com social networking script (psisns), probably 1.0, allows remote attackers to execute arbitrary SQL commands via the u parameter.
0
Attacker Value
Unknown
CVE-2007-2199
Disclosure Date: April 24, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vincent Blavet PhpConcept Library, as used in multiple products including (1) Joomla! 1.5.0 Beta, (2) N/X Web Content Management System (WCMS) 4.5, (3) CJG EXPLORER PRO 3.3, and (4) phpSiteBackup 0.1, allows remote attackers to execute arbitrary PHP code via a URL in the g_pcltar_lib_dir parameter.
0
Attacker Value
Unknown
CVE-2007-2155
Disclosure Date: April 19, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in template.php in in phpFaber TopSites 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the modify parameter in a template action to admin/index.php.
0
Attacker Value
Unknown
CVE-2007-1844
Disclosure Date: April 03, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Aardvark Topsites PHP 5 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) button/settings_sql.php, (2) settings_sql.php, and (3) sources/misc/new_day.php.
0
Attacker Value
Unknown
CVE-2007-1650
Disclosure Date: March 24, 2007 (last updated October 04, 2023)
pcapsipdump.cpp in pcapsipdump before 0.1.3 allows remote attackers to cause a denial of service (application crash) via a malformed SIP packet, which results in a NULL pointer dereference.
0