Show filters
57 Total Results
Displaying 51-57 of 57
Sort by:
Attacker Value
Unknown
CVE-2014-2858
Disclosure Date: April 15, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 through 2.3.6 allows remote attackers to obtain sensitive information via unspecified vectors related to a "configured block." NOTE: this issue was SPLIT from CVE-2014-0053 per ADT2 due to different vulnerability types.
0
Attacker Value
Unknown
CVE-2014-0053
Disclosure Date: April 15, 2014 (last updated October 05, 2023)
The default configuration of the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 before 2.3.6 does not properly restrict access to files in the WEB-INF directory, which allows remote attackers to obtain sensitive information via a direct request. NOTE: this identifier has been SPLIT due to different researchers and different vulnerability types. See CVE-2014-2857 for the META-INF variant and CVE-2014-2858 for the directory traversal.
0
Attacker Value
Unknown
CVE-2011-4311
Disclosure Date: November 19, 2011 (last updated October 04, 2023)
ResourceSpace before 4.2.2833 does not properly validate access keys, which allows remote attackers to bypass intended resource restrictions via unspecified vectors.
0
Attacker Value
Unknown
CVE-2009-4397
Disclosure Date: December 22, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Diocese of Portsmouth Resources Database (pd_resources) extension 0.1.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2009-4396
Disclosure Date: December 22, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the Diocese of Portsmouth Resources Database (pd_resources) extension 0.1.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-1844
Disclosure Date: April 16, 2008 (last updated October 04, 2023)
SQL injection vulnerability in cat.php in W2B phpHotResources allows remote attackers to execute arbitrary SQL commands via the kind parameter.
0
Attacker Value
Unknown
CVE-2005-4165
Disclosure Date: December 11, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in ASP-DEV ASP Resources Forum allow remote attackers to execute arbitrary SQL commands via the (1) forum_id parameter to forum.asp, (2) unspecified parameters to register.asp, and (3) the "Search For" field in search.asp.
0