Show filters
61 Total Results
Displaying 51-60 of 61
Sort by:
Attacker Value
Unknown

CVE-2010-5200

Disclosure Date: September 06, 2012 (last updated October 05, 2023)
Untrusted search path vulnerability in KeePass Password Safe before 1.18 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .kdb file. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2010-5196

Disclosure Date: September 06, 2012 (last updated October 05, 2023)
Untrusted search path vulnerability in KeePass Password Safe before 2.13 allows local users to gain privileges via a Trojan horse DwmApi.dll file in the current working directory, as demonstrated by a directory that contains a .kdbx file. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2011-1784

Disclosure Date: May 20, 2011 (last updated October 04, 2023)
The pidfile_write function in core/pidfile.c in keepalived 1.2.2 and earlier uses 0666 permissions for the (1) keepalived.pid, (2) checkers.pid, and (3) vrrp.pid files in /var/run/, which allows local users to kill arbitrary processes by writing a PID to one of these files.
0
Attacker Value
Unknown

CVE-2009-0287

Disclosure Date: January 27, 2009 (last updated October 04, 2023)
SQL injection vulnerability in lib/patUser.php in KEEP Toolkit before 2.5.1 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password.
0
Attacker Value
Unknown

CVE-2008-2774

Disclosure Date: June 19, 2008 (last updated October 04, 2023)
SQL injection vulnerability in item.php in CartKeeper CKGold Shopping Cart 2.5 and 2.7 allows remote attackers to execute arbitrary SQL commands via the category_id parameter, a different vector than CVE-2007-4736.
0
Attacker Value
Unknown

CVE-2007-4736

Disclosure Date: September 06, 2007 (last updated October 04, 2023)
SQL injection vulnerability in category.php in CartKeeper CKGold Shopping Cart 2.0 allows remote attackers to execute arbitrary SQL commands via the category_id parameter.
0
Attacker Value
Unknown

CVE-2007-4375

Disclosure Date: August 16, 2007 (last updated October 04, 2023)
The administrative interface (aka DkService.exe) in Diskeeper 9 Professional, 2007 Pro Premier, and probably other versions exposes a memory comparison function via RPC over TCP, which allows remote attackers to (1) obtain sensitive information (process memory contents), as demonstrated by an attack that obtains module base addresses to defeat Address Space Layout Randomization (ASLR); or (2) cause a denial of service (application crash) via an out-of-bounds address.
0
Attacker Value
Unknown

CVE-2006-6764

Disclosure Date: December 27, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in authenticate.php in Keep It Simple Guest Book (KISGB), when executing PHP through CGI, allows remote attackers to execute arbitrary PHP code via a URL in the default_path_to_themes parameter.
0
Attacker Value
Unknown

CVE-2006-6763

Disclosure Date: December 27, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in the Keep It Simple Guest Book (KISGB) allow remote attackers to execute arbitrary PHP code via a URL in the (1) path_to_themes parameter in (a) authenticate.php, and the (2) default_path_for_themes parameter in (b) admin.php and (c) upconfig.php.
0
Attacker Value
Unknown

CVE-2006-5018

Disclosure Date: September 27, 2006 (last updated October 04, 2023)
ContentKeeper 123.25 and earlier places passwords in cleartext in an INPUT element in cgi-bin/ck/changepw.cgi, which allows remote authenticated users to obtain passwords via this URI.
0