Show filters
74 Total Results
Displaying 61-70 of 74
Sort by:
Attacker Value
Unknown
CVE-2009-1664
Disclosure Date: May 18, 2009 (last updated October 04, 2023)
myaccount.php in Easy Scripts Answer and Question Script does not verify the original password before changing passwords, which allows remote attackers to change the password of other users and gain privileges via modified userid, txtpassword, and txtRpassword parameters.
0
Attacker Value
Unknown
CVE-2009-1663
Disclosure Date: May 18, 2009 (last updated October 04, 2023)
Unrestricted file upload vulnerability in myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the uploads/[username] directory.
0
Attacker Value
Unknown
CVE-2009-1654
Disclosure Date: May 16, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in questiondetail.php in Easy Scripts Answer and Question Script allows remote attackers to inject arbitrary web script or HTML via the questionid parameter.
0
Attacker Value
Unknown
CVE-2009-1655
Disclosure Date: May 16, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in myaccount.php in Easy Scripts Answer and Question Script allow remote authenticated users to execute arbitrary SQL commands via the (1) user name (userid parameter) and (2) password.
0
Attacker Value
Unknown
CVE-2008-6413
Disclosure Date: March 06, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Answers module 5.x-1.x-dev and possibly other 5.x versions, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a Simple Answer to a question.
0
Attacker Value
Unknown
CVE-2008-5490
Disclosure Date: December 12, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in PHPStore Yahoo Answers allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown
CVE-2007-6387
Disclosure Date: December 15, 2007 (last updated October 04, 2023)
Multiple stack-based buffer overflows in the awApi4.AnswerWorks.1 ActiveX control in awApi4.dll 4.0.0.42, as used by Vantage Linguistics AnswerWorks, and Intuit Clearly Bookkeeping, ProSeries, QuickBooks, Quicken, QuickTax, and TurboTax, allow remote attackers to execute arbitrary code via long arguments to the (1) GetHistory, (2) GetSeedQuery, (3) SetSeedQuery, and possibly other methods. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2005-0549
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the "View Log Files" function.
0
Attacker Value
Unknown
CVE-2005-0548
Disclosure Date: March 07, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the Search function.
0
Attacker Value
Unknown
CVE-2002-2425
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Sun AnswerBook2 1.2 through 1.4.2 allows remote attackers to execute administrative scripts such as (1) AdminViewError and (2) AdminAddadmin via a direct request.
0