Show filters
735 Total Results
Displaying 581-590 of 735
Sort by:
Attacker Value
Unknown

CVE-2010-5219

Disclosure Date: September 06, 2012 (last updated October 05, 2023)
Untrusted search path vulnerability in SmartFTP 4.0.1140.0 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .txt, .html, or .mpg file. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2012-4277

Disclosure Date: August 13, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the smarty_function_html_options_optoutput function in distribution/libs/plugins/function.html_options.php in Smarty before 3.1.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-3438

Disclosure Date: August 07, 2012 (last updated October 04, 2023)
The Magick_png_malloc function in coders/png.c in GraphicsMagick 6.7.8-6 does not use the proper variable type for the allocation size, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG file that triggers incorrect memory allocation.
0
Attacker Value
Unknown

CVE-2012-2913

Disclosure Date: May 21, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Leaflet plugin 0.0.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) leaflet_layer.php or (2) leaflet_marker.php, as reachable through wp-admin/admin.php.
0
Attacker Value
Unknown

CVE-2012-1992

Disclosure Date: April 11, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in admin/edituser.php in CMS Made Simple 1.10.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the email parameter (aka the Email Address field in the Edit User template).
0
Attacker Value
Unknown

CVE-2012-1066

Disclosure Date: February 14, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the template module in SmartyCMS 0.9.4 allows remote attackers to inject arbitrary web script or HTML via the title bar.
0
Attacker Value
Unknown

CVE-2011-4752

Disclosure Date: December 16, 2011 (last updated October 04, 2023)
SmarterTools SmarterStats 6.2.4100 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving frmCustomReport.aspx and certain other files. NOTE: it is possible that only clients, not the SmarterStats product, could be affected by this issue.
0
Attacker Value
Unknown

CVE-2011-4751

Disclosure Date: December 16, 2011 (last updated October 04, 2023)
SmarterTools SmarterStats 6.2.4100 generates web pages containing external links in response to GET requests with query strings for frmGettingStarted.aspx, which makes it easier for remote attackers to obtain sensitive information by reading (1) web-server access logs or (2) web-server Referer logs, related to a "cross-domain Referer leakage" issue.
0
Attacker Value
Unknown

CVE-2011-4750

Disclosure Date: December 16, 2011 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in SmarterTools SmarterStats 6.2.4100 allow remote attackers to inject arbitrary web script or HTML via crafted input to a PHP script, as demonstrated by Default.aspx and certain other files.
0
Attacker Value
Unknown

CVE-2010-4871

Disclosure Date: October 07, 2011 (last updated October 04, 2023)
Unspecified vulnerability in SmartFTP before 4.0 Build 1142 allows attackers to have an unknown impact via a long filename.
0