Show filters
536 Total Results
Displaying 501-510 of 536
Sort by:
Attacker Value
Unknown

CVE-2006-0670

Disclosure Date: February 13, 2006 (last updated February 22, 2025)
Buffer overflow in l2cap.c in hcidump 1.29 allows remote attackers to cause a denial of service (crash) through a wireless Bluetooth connection via a malformed Logical Link Control and Adaptation Protocol (L2CAP) packet.
0
Attacker Value
Unknown

CVE-2006-0159

Disclosure Date: January 10, 2006 (last updated February 22, 2025)
SQL injection vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to execute arbitrary SQL commands via the email parameter. NOTE: the provenance of this information is unknown, although it may be based on post-disclosure analysis of CVE-2006-0110; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2006-0146

Disclosure Date: January 09, 2006 (last updated February 22, 2025)
The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter.
0
Attacker Value
Unknown

CVE-2006-0110

Disclosure Date: January 07, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to inject arbitrary web script via the email parameter.
0
Attacker Value
Unknown

CVE-2005-4854

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
eZ publish 3.5 through 3.7 before 20050830 does not use a folder's read permissions to restrict notifications, which allows remote authenticated users to obtain sensitive information about changes to content in arbitrary folders.
0
Attacker Value
Unknown

CVE-2005-4850

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
eZ publish 3.5 through 3.7 before 20050608 requires both edit and create permissions in order to submit data, which allows remote attackers to edit data submitted by arbitrary anonymous users.
0
Attacker Value
Unknown

CVE-2005-4852

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
The siteaccess URIMatching implementation in eZ publish 3.5 through 3.8 before 20050812 converts all non-alphanumeric characters in a URI to '_' (underscore), which allows remote attackers to bypass access restrictions by inserting certain characters in a URI, as demonstrated by a request for /admin:de, which matches a rule allowing only /admin_de to access /admin.
0
Attacker Value
Unknown

CVE-2005-4851

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
eZ publish 3.4.4 through 3.7 before 20050722 applies certain permissions on the node level, which allows remote authenticated users to bypass the original permissions on embedded objects in XML fields and read these objects.
0
Attacker Value
Unknown

CVE-2005-4856

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
The admin interface in eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051110 does not properly handle authorization errors, which allows remote attackers to obtain sensitive information and see the admin pagelayout and associated templates via a request with (1) "anything after the url" or (2) a "wrong url".
0
Attacker Value
Unknown

CVE-2005-4853

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
The default configuration of the forum package in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050818 does not restrict edit permissions to a posting's owner, which allows remote authenticated users to edit arbitrary postings.
0