Show filters
92 Total Results
Displaying 51-60 of 92
Sort by:
Attacker Value
Unknown

CVE-2008-3539

Disclosure Date: September 11, 2008 (last updated October 04, 2023)
Unspecified vulnerability in HP OpenView Select Identity (HPSI) Connectors on Windows, as used in HPSI Active Directory Connector 2.30 and earlier, HPSI SunOne Connector 1.14 and earlier, HPSI eDirectory Connector 1.12 and earlier, HPSI eTrust Connector 1.02 and earlier, HPSI OID Connector 1.02 and earlier, HPSI IBM Tivoli Dir Connector 1.02 and earlier, HPSI TOPSecret Connector 2.22.001 and earlier, HPSI RACF Connector 1.12.001 and earlier, HPSI ACF2 Connector 1.02 and earlier, HPSI OpenLDAP Connector 1.02 and earlier, and HPSI BiDir DirX Connector 1.00.003 and earlier, allows local users to obtain sensitive information via unknown vectors.
0
Attacker Value
Unknown

CVE-2008-3598

Disclosure Date: August 12, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in psipuss 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the Cid parameter to categories.php or (2) the Username parameter to login.php.
0
Attacker Value
Unknown

CVE-2008-1665

Disclosure Date: July 17, 2008 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in HP Select Identity (HPSI) Active Directory Bidirectional LDAP Connector 2.20, 2.20.001, 2.20.002, and 2.30 allow remote attackers to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-1784

Disclosure Date: April 15, 2008 (last updated October 04, 2023)
Prozilla Topsites 1.0 allows remote attackers to perform administrative actions via a direct request to (1) addu.php, (2) editu.php, and (3) uidx.php in siteadmin/.
0
Attacker Value
Unknown

CVE-2007-5918

Disclosure Date: November 10, 2007 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in edit.php in the MS TopSites add-on for PHP-Nuke does not verify that the uname parameter matches the current account, which allows remote authenticated users to change arbitrary accounts or change the SiteTitleName field as an arbitrary user via a modified uname value in an edit action to modules.php.
0
Attacker Value
Unknown

CVE-2007-4881

Disclosure Date: September 14, 2007 (last updated October 04, 2023)
SQL injection vulnerability in profile/myprofile.php in psi-labs.com social networking script (psisns), probably 1.0, allows remote attackers to execute arbitrary SQL commands via the u parameter.
0
Attacker Value
Unknown

CVE-2007-2199

Disclosure Date: April 24, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vincent Blavet PhpConcept Library, as used in multiple products including (1) Joomla! 1.5.0 Beta, (2) N/X Web Content Management System (WCMS) 4.5, (3) CJG EXPLORER PRO 3.3, and (4) phpSiteBackup 0.1, allows remote attackers to execute arbitrary PHP code via a URL in the g_pcltar_lib_dir parameter.
0
Attacker Value
Unknown

CVE-2007-2155

Disclosure Date: April 19, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in template.php in in phpFaber TopSites 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the modify parameter in a template action to admin/index.php.
0
Attacker Value
Unknown

CVE-2007-1844

Disclosure Date: April 03, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Aardvark Topsites PHP 5 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) button/settings_sql.php, (2) settings_sql.php, and (3) sources/misc/new_day.php.
0
Attacker Value
Unknown

CVE-2007-1650

Disclosure Date: March 24, 2007 (last updated October 04, 2023)
pcapsipdump.cpp in pcapsipdump before 0.1.3 allows remote attackers to cause a denial of service (application crash) via a malformed SIP packet, which results in a NULL pointer dereference.
0