Show filters
601 Total Results
Displaying 511-520 of 601
Sort by:
Attacker Value
Unknown

CVE-2010-4184

Disclosure Date: November 05, 2010 (last updated October 04, 2023)
NetSupport Manager (NSM) before 11.00.0005 sends HTTP headers with cleartext fields containing details about client machines, which allows remote attackers to obtain potentially sensitive information by sniffing the network.
0
Attacker Value
Unknown

CVE-2010-2911

Disclosure Date: July 28, 2010 (last updated October 04, 2023)
SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a viewnews action.
0
Attacker Value
Unknown

CVE-2010-2912

Disclosure Date: July 28, 2010 (last updated October 04, 2023)
SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands via the _a parameter in a downloads action.
0
Attacker Value
Unknown

CVE-2009-4861

Disclosure Date: May 11, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in shownews.php in SupportPRO SupportDesk 3.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
0
Attacker Value
Unknown

CVE-2010-1596

Disclosure Date: April 28, 2010 (last updated October 04, 2023)
Support Incident Tracker before 3.51, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.
0
Attacker Value
Unknown

CVE-2009-4777

Disclosure Date: April 21, 2010 (last updated October 04, 2023)
Unspecified vulnerability in multiple versions of Hitachi JP1/Automatic Job Management System 2 - View, JP1/Integrated Management - View, and JP1/Cm2/SNMP System Observer, allows remote attackers to cause a denial of service ("abnormal" termination) via vectors related to the display of an "invalid GIF file."
0
Attacker Value
Unknown

CVE-2010-0460

Disclosure Date: January 28, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in staff/index.php in Kayako SupportSuite 3.60.04 and earlier allow remote authenticated users to inject arbitrary web script or HTML via the (1) subject parameter and (2) contents parameter (aka body) in an insertquestion action. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2009-4542

Disclosure Date: January 04, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in newticket.php in IsolSoft Support Center 2.5 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
0
Attacker Value
Unknown

CVE-2009-4541

Disclosure Date: January 04, 2010 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in IsolSoft Support Center 2.5 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) newticket.php or (2) rempass.php, or a URL in the lang parameter in an adduser action to (3) index.php. NOTE: this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences.
0
Attacker Value
Unknown

CVE-2009-4434

Disclosure Date: December 28, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in IDevSpot iSupport 1.8 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the include_file parameter.
0