Show filters
601 Total Results
Displaying 511-520 of 601
Sort by:
Attacker Value
Unknown
CVE-2010-4184
Disclosure Date: November 05, 2010 (last updated October 04, 2023)
NetSupport Manager (NSM) before 11.00.0005 sends HTTP headers with cleartext fields containing details about client machines, which allows remote attackers to obtain potentially sensitive information by sniffing the network.
0
Attacker Value
Unknown
CVE-2010-2911
Disclosure Date: July 28, 2010 (last updated October 04, 2023)
SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a viewnews action.
0
Attacker Value
Unknown
CVE-2010-2912
Disclosure Date: July 28, 2010 (last updated October 04, 2023)
SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands via the _a parameter in a downloads action.
0
Attacker Value
Unknown
CVE-2009-4861
Disclosure Date: May 11, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in shownews.php in SupportPRO SupportDesk 3.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
0
Attacker Value
Unknown
CVE-2010-1596
Disclosure Date: April 28, 2010 (last updated October 04, 2023)
Support Incident Tracker before 3.51, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.
0
Attacker Value
Unknown
CVE-2009-4777
Disclosure Date: April 21, 2010 (last updated October 04, 2023)
Unspecified vulnerability in multiple versions of Hitachi JP1/Automatic Job Management System 2 - View, JP1/Integrated Management - View, and JP1/Cm2/SNMP System Observer, allows remote attackers to cause a denial of service ("abnormal" termination) via vectors related to the display of an "invalid GIF file."
0
Attacker Value
Unknown
CVE-2010-0460
Disclosure Date: January 28, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in staff/index.php in Kayako SupportSuite 3.60.04 and earlier allow remote authenticated users to inject arbitrary web script or HTML via the (1) subject parameter and (2) contents parameter (aka body) in an insertquestion action. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2009-4542
Disclosure Date: January 04, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in newticket.php in IsolSoft Support Center 2.5 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
0
Attacker Value
Unknown
CVE-2009-4541
Disclosure Date: January 04, 2010 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in IsolSoft Support Center 2.5 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) newticket.php or (2) rempass.php, or a URL in the lang parameter in an adduser action to (3) index.php. NOTE: this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences.
0
Attacker Value
Unknown
CVE-2009-4434
Disclosure Date: December 28, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in IDevSpot iSupport 1.8 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the include_file parameter.
0