Show filters
536 Total Results
Displaying 501-510 of 536
Sort by:
Attacker Value
Unknown
CVE-2006-0670
Disclosure Date: February 13, 2006 (last updated February 22, 2025)
Buffer overflow in l2cap.c in hcidump 1.29 allows remote attackers to cause a denial of service (crash) through a wireless Bluetooth connection via a malformed Logical Link Control and Adaptation Protocol (L2CAP) packet.
0
Attacker Value
Unknown
CVE-2006-0159
Disclosure Date: January 10, 2006 (last updated February 22, 2025)
SQL injection vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to execute arbitrary SQL commands via the email parameter. NOTE: the provenance of this information is unknown, although it may be based on post-disclosure analysis of CVE-2006-0110; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2006-0146
Disclosure Date: January 09, 2006 (last updated February 22, 2025)
The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter.
0
Attacker Value
Unknown
CVE-2006-0110
Disclosure Date: January 07, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to inject arbitrary web script via the email parameter.
0
Attacker Value
Unknown
CVE-2005-4854
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
eZ publish 3.5 through 3.7 before 20050830 does not use a folder's read permissions to restrict notifications, which allows remote authenticated users to obtain sensitive information about changes to content in arbitrary folders.
0
Attacker Value
Unknown
CVE-2005-4850
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
eZ publish 3.5 through 3.7 before 20050608 requires both edit and create permissions in order to submit data, which allows remote attackers to edit data submitted by arbitrary anonymous users.
0
Attacker Value
Unknown
CVE-2005-4852
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
The siteaccess URIMatching implementation in eZ publish 3.5 through 3.8 before 20050812 converts all non-alphanumeric characters in a URI to '_' (underscore), which allows remote attackers to bypass access restrictions by inserting certain characters in a URI, as demonstrated by a request for /admin:de, which matches a rule allowing only /admin_de to access /admin.
0
Attacker Value
Unknown
CVE-2005-4851
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
eZ publish 3.4.4 through 3.7 before 20050722 applies certain permissions on the node level, which allows remote authenticated users to bypass the original permissions on embedded objects in XML fields and read these objects.
0
Attacker Value
Unknown
CVE-2005-4856
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
The admin interface in eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051110 does not properly handle authorization errors, which allows remote attackers to obtain sensitive information and see the admin pagelayout and associated templates via a request with (1) "anything after the url" or (2) a "wrong url".
0
Attacker Value
Unknown
CVE-2005-4853
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
The default configuration of the forum package in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050818 does not restrict edit permissions to a posting's owner, which allows remote authenticated users to edit arbitrary postings.
0