Show filters
87 Total Results
Displaying 51-60 of 87
Sort by:
Attacker Value
Unknown
CVE-2009-4495
Disclosure Date: January 13, 2010 (last updated October 04, 2023)
Yaws 1.85 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.
0
Attacker Value
Unknown
CVE-2009-2233
Disclosure Date: June 26, 2009 (last updated October 04, 2023)
The admin interface in AWScripts.com Gallery Search Engine 1.5 allows remote attackers to bypass authentication and gain administrative access by setting the awse_logged cookie to 1.
0
Attacker Value
Unknown
CVE-2009-0751
Disclosure Date: March 02, 2009 (last updated October 04, 2023)
Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with a large number of headers.
0
Attacker Value
Unknown
CVE-2009-0645
Disclosure Date: February 18, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in Jaws 0.8.8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) language, (2) Introduction_complete, and (3) use_log parameters, different vectors than CVE-2004-2445.
0
Attacker Value
Unknown
CVE-2008-5722
Disclosure Date: December 26, 2008 (last updated October 04, 2023)
Buffer overflow in SAWStudio 3.9i allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long SAWSTUDIO PREFERENCES STRUCT value in a .prf (preferences) file.
0
Attacker Value
Unknown
CVE-2008-5080
Disclosure Date: December 03, 2008 (last updated November 08, 2023)
awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the query_string parameter. NOTE: this issue exists because of an incomplete fix for CVE-2008-3714.
0
Attacker Value
Unknown
CVE-2008-4600
Disclosure Date: October 18, 2008 (last updated October 04, 2023)
configure.php in PokerMax Poker League Tournament Script 0.13 allows remote attackers to bypass authentication and gain administrative access by setting the ValidUserAdmin cookie.
0
Attacker Value
Unknown
CVE-2008-3714
Disclosure Date: August 19, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via the query_string, a different vulnerability than CVE-2006-3681 and CVE-2006-1945.
0
Attacker Value
Unknown
CVE-2007-6208
Disclosure Date: December 04, 2007 (last updated October 04, 2023)
sylprint.pl in claws mail tools (claws-mail-tools) allows local users to overwrite arbitrary files via a symlink attack on the sylprint.[USER].[PID] temporary file.
0
Attacker Value
Unknown
CVE-2007-2958
Disclosure Date: August 27, 2007 (last updated October 04, 2023)
Format string vulnerability in the inc_put_error function in src/inc.c in Sylpheed 2.4.4, and Sylpheed-Claws (Claws Mail) 1.9.100 and 2.10.0, allows remote POP3 servers to execute arbitrary code via format string specifiers in crafted replies.
0