Show filters
601 Total Results
Displaying 531-540 of 601
Sort by:
Attacker Value
Unknown
CVE-2008-5783
Disclosure Date: December 31, 2008 (last updated October 04, 2023)
admin/index.php in V3 Chat Live Support 3.0.4 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1.
0
Attacker Value
Unknown
CVE-2008-5717
Disclosure Date: December 26, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Hitachi JP1/Integrated Management - Service Support 08-10 through 08-10-05, 08-11 through 08-11-03, and 08-50 through 08-50-03 on Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-4761
Disclosure Date: October 28, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in includes/htmlArea/plugins/HtmlTidy/html-tidy-logic.php in Kayako eSupport 3.20.2 allows remote attackers to inject arbitrary web script or HTML via the jsMakeSrc parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this issue is probably in the HTMLArea HTMLTidy (HTML Tidy) plugin, not eSupport.
0
Attacker Value
Unknown
CVE-2008-3701
Disclosure Date: August 15, 2008 (last updated October 04, 2023)
SQL injection vulnerability in staff/index.php in Kayako SupportSuite 3.20.02 and earlier allows remote authenticated users to execute arbitrary SQL commands via the customfieldlinkid parameter in a delcflink action.
0
Attacker Value
Unknown
CVE-2008-3700
Disclosure Date: August 15, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite 3.20.02 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the sessionid parameter in a livesupport startclientchat action to visitor/index.php; (2) the filter parameter in a news view action to index.php; or the Full Name field in a (3) account creation, (4) ticket opening, or (5) chat request operation.
0
Attacker Value
Unknown
CVE-2008-3055
Disclosure Date: July 07, 2008 (last updated October 04, 2023)
SQL injection vulnerability in the Support view (ext_tbl) extension 0.0.102 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-2763
Disclosure Date: June 18, 2008 (last updated October 04, 2023)
SQL injection vulnerability in search.asp in Xigla Absolute Live Support XE 5.1 allows remote authenticated administrators to execute arbitrary SQL commands via the orderby parameter.
0
Attacker Value
Unknown
CVE-2008-2764
Disclosure Date: June 18, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in admin/search.asp in Xigla Absolute Live Support XE 5.1 allows remote authenticated administrators to inject arbitrary web script or HTML via unspecified vectors ("all fields").
0
Attacker Value
Unknown
CVE-2007-5604
Disclosure Date: June 04, 2008 (last updated October 04, 2023)
Buffer overflow in the ExtractCab function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary code via a long first argument, a different vulnerability than CVE-2007-5605, CVE-2007-5606, and CVE-2007-5607.
0
Attacker Value
Unknown
CVE-2007-5607
Disclosure Date: June 04, 2008 (last updated October 04, 2023)
Buffer overflow in the RegistryString function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary code via a long first argument, a different vulnerability than CVE-2007-5604, CVE-2007-5605, and CVE-2007-5606.
0