Show filters
601 Total Results
Displaying 531-540 of 601
Sort by:
Attacker Value
Unknown

CVE-2008-5783

Disclosure Date: December 31, 2008 (last updated October 04, 2023)
admin/index.php in V3 Chat Live Support 3.0.4 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1.
0
Attacker Value
Unknown

CVE-2008-5717

Disclosure Date: December 26, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Hitachi JP1/Integrated Management - Service Support 08-10 through 08-10-05, 08-11 through 08-11-03, and 08-50 through 08-50-03 on Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-4761

Disclosure Date: October 28, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in includes/htmlArea/plugins/HtmlTidy/html-tidy-logic.php in Kayako eSupport 3.20.2 allows remote attackers to inject arbitrary web script or HTML via the jsMakeSrc parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this issue is probably in the HTMLArea HTMLTidy (HTML Tidy) plugin, not eSupport.
0
Attacker Value
Unknown

CVE-2008-3701

Disclosure Date: August 15, 2008 (last updated October 04, 2023)
SQL injection vulnerability in staff/index.php in Kayako SupportSuite 3.20.02 and earlier allows remote authenticated users to execute arbitrary SQL commands via the customfieldlinkid parameter in a delcflink action.
0
Attacker Value
Unknown

CVE-2008-3700

Disclosure Date: August 15, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite 3.20.02 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the sessionid parameter in a livesupport startclientchat action to visitor/index.php; (2) the filter parameter in a news view action to index.php; or the Full Name field in a (3) account creation, (4) ticket opening, or (5) chat request operation.
0
Attacker Value
Unknown

CVE-2008-3055

Disclosure Date: July 07, 2008 (last updated October 04, 2023)
SQL injection vulnerability in the Support view (ext_tbl) extension 0.0.102 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-2763

Disclosure Date: June 18, 2008 (last updated October 04, 2023)
SQL injection vulnerability in search.asp in Xigla Absolute Live Support XE 5.1 allows remote authenticated administrators to execute arbitrary SQL commands via the orderby parameter.
0
Attacker Value
Unknown

CVE-2008-2764

Disclosure Date: June 18, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in admin/search.asp in Xigla Absolute Live Support XE 5.1 allows remote authenticated administrators to inject arbitrary web script or HTML via unspecified vectors ("all fields").
0
Attacker Value
Unknown

CVE-2007-5604

Disclosure Date: June 04, 2008 (last updated October 04, 2023)
Buffer overflow in the ExtractCab function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary code via a long first argument, a different vulnerability than CVE-2007-5605, CVE-2007-5606, and CVE-2007-5607.
0
Attacker Value
Unknown

CVE-2007-5607

Disclosure Date: June 04, 2008 (last updated October 04, 2023)
Buffer overflow in the RegistryString function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary code via a long first argument, a different vulnerability than CVE-2007-5604, CVE-2007-5605, and CVE-2007-5606.
0