Show filters
57 Total Results
Displaying 51-57 of 57
Sort by:
Attacker Value
Unknown

CVE-2006-6213

Disclosure Date: December 01, 2006 (last updated October 04, 2023)
index.php in PEGames uses the extract function to overwrite critical variables, which allows remote attackers to conduct PHP remote file inclusion attacks via the abs_url parameter, which is later extracted to overwrite a previously uncontrolled value.
0
Attacker Value
Unknown

CVE-2006-5961

Disclosure Date: November 17, 2006 (last updated October 04, 2023)
Buffer overflow in Mercury Mail Transport System 4.01b for Windows has unknown impact and attack vectors, as originally reported in a GLEG VulnDisco pack. NOTE: the provenance of this information is unknown; the details are obtained from third party information. The original researcher is reliable.
0
Attacker Value
Unknown

CVE-2006-1826

Disclosure Date: April 18, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Snipe Gallery 3.1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gallery_id parameter in view.php, (2) keyword parameter in search.php, and (3) image_id parameter in image.php. NOTE: it is possible that vectors 1 and 3 are resultant from SQL injection.
0
Attacker Value
Unknown

CVE-2005-4244

Disclosure Date: December 14, 2005 (last updated February 22, 2025)
SQL injection vulnerability in Snipe Gallery 3.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) gallery_id parameter to view.php and (2) image_id parameter to image.php.
0
Attacker Value
Unknown

CVE-2005-4245

Disclosure Date: December 14, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in search.php in Snipe Gallery 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.
0
Attacker Value
Unknown

CVE-2004-2617

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Directory traversal vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to read files outside of the web root via a .. (dot dot) directly after the initial '/' (slash) in the URI.
0
Attacker Value
Unknown

CVE-2004-2618

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to inject arbitrary web script or HTML via the URI, directly after the initial '/' (slash).
0