Show filters
57 Total Results
Displaying 51-57 of 57
Sort by:
Attacker Value
Unknown
CVE-2006-6213
Disclosure Date: December 01, 2006 (last updated October 04, 2023)
index.php in PEGames uses the extract function to overwrite critical variables, which allows remote attackers to conduct PHP remote file inclusion attacks via the abs_url parameter, which is later extracted to overwrite a previously uncontrolled value.
0
Attacker Value
Unknown
CVE-2006-5961
Disclosure Date: November 17, 2006 (last updated October 04, 2023)
Buffer overflow in Mercury Mail Transport System 4.01b for Windows has unknown impact and attack vectors, as originally reported in a GLEG VulnDisco pack. NOTE: the provenance of this information is unknown; the details are obtained from third party information. The original researcher is reliable.
0
Attacker Value
Unknown
CVE-2006-1826
Disclosure Date: April 18, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Snipe Gallery 3.1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gallery_id parameter in view.php, (2) keyword parameter in search.php, and (3) image_id parameter in image.php. NOTE: it is possible that vectors 1 and 3 are resultant from SQL injection.
0
Attacker Value
Unknown
CVE-2005-4244
Disclosure Date: December 14, 2005 (last updated February 22, 2025)
SQL injection vulnerability in Snipe Gallery 3.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) gallery_id parameter to view.php and (2) image_id parameter to image.php.
0
Attacker Value
Unknown
CVE-2005-4245
Disclosure Date: December 14, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in search.php in Snipe Gallery 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.
0
Attacker Value
Unknown
CVE-2004-2617
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Directory traversal vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to read files outside of the web root via a .. (dot dot) directly after the initial '/' (slash) in the URI.
0
Attacker Value
Unknown
CVE-2004-2618
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to inject arbitrary web script or HTML via the URI, directly after the initial '/' (slash).
0