Show filters
61 Total Results
Displaying 51-60 of 61
Sort by:
Attacker Value
Unknown
CVE-2008-0760
Disclosure Date: February 13, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.4.1.0 and earlier, and Sentinel Keys Server 1.0.4.0 and earlier, allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the URI. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-6483.
0
Attacker Value
Unknown
CVE-2008-0351
Disclosure Date: January 18, 2008 (last updated October 04, 2023)
admin/config.php in Evilsentinel 1.0.9 and earlier allows remote attackers to bypass the CAPTCHA test by omitting the es_security_captcha parameter and not invoking captcha.php.
0
Attacker Value
Unknown
CVE-2008-0350
Disclosure Date: January 18, 2008 (last updated October 04, 2023)
admin/index.php in Evilsentinel 1.0.9 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to gain administrative privileges and make arbitrary configuration changes.
0
Attacker Value
Unknown
CVE-2007-6483
Disclosure Date: December 20, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.0.0 through 7.4.0 and possibly earlier versions, and Sentinel Keys Server 1.0.3 and possibly earlier versions, allows remote attackers to read arbitrary files via a .. (dot dot) in the query string.
0
Attacker Value
Unknown
CVE-2007-5151
Disclosure Date: October 01, 2007 (last updated October 04, 2023)
SQL injection vulnerability in the abget_admin function in includes/nukesentinel.php in NukeSentinel 2.5.12 allows remote attackers to execute arbitrary SQL commands via base64-encoded data in an admin cookie.
0
Attacker Value
Unknown
CVE-2007-5150
Disclosure Date: October 01, 2007 (last updated October 04, 2023)
SQL injection vulnerability in the is_god function in includes/nukesentinel.php in NukeSentinel 2.5.11 allows remote attackers to execute arbitrary SQL commands via base64-encoded data in an admin cookie, a different vector than CVE-2007-5125.
0
Attacker Value
Unknown
CVE-2007-1494
Disclosure Date: March 16, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in NukeSentinel before 2.5.06 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the "filters for https:// and http://".
0
Attacker Value
Unknown
CVE-2007-1493
Disclosure Date: March 16, 2007 (last updated October 04, 2023)
nukesentinel.php in NukeSentinel 2.5.06 and earlier uses a permissive regular expression to validate an IP address, which allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, due to an incomplete patch for CVE-2007-1172.
0
Attacker Value
Unknown
CVE-2007-1172
Disclosure Date: March 02, 2007 (last updated October 04, 2023)
SQL injection vulnerability in nukesentinel.php in NukeSentinel 2.5.05, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, aka the "File Disclosure Exploit."
0
Attacker Value
Unknown
CVE-2007-1171
Disclosure Date: March 02, 2007 (last updated October 04, 2023)
SQL injection vulnerability in includes/nsbypass.php in NukeSentinel 2.5.05, 2.5.11, and other versions before 2.5.12 allows remote attackers to execute arbitrary SQL commands via an admin cookie.
0