Show filters
70 Total Results
Displaying 61-70 of 70
Sort by:
Attacker Value
Unknown
CVE-2013-1933
Disclosure Date: April 25, 2013 (last updated October 05, 2023)
The extract_from_ocr function in lib/docsplit/text_extractor.rb in the Karteek Docsplit (karteek-docsplit) gem 0.5.4 for Ruby allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a PDF filename.
0
Attacker Value
Unknown
CVE-2011-3645
Disclosure Date: September 27, 2011 (last updated October 04, 2023)
Newgen OmniDocs allows remote attackers to bypass intended access restrictions via (1) a modified FolderRights parameter to doccab/doclist.jsp, which leads to arbitrary permission changes; or (2) a modified UserIndex parameter to doccab/userprofile/editprofile.jsp, which selects the settings page of an arbitrary user.
0
Attacker Value
Unknown
CVE-2010-0701
Disclosure Date: February 23, 2010 (last updated October 04, 2023)
SQL injection vulnerability in ForceChangePassword.jsp in Newgen Software OmniDocs allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2007-4750
Disclosure Date: September 18, 2007 (last updated October 04, 2023)
Unspecified vulnerability in RemoteDocs R-Viewer before 1.6.3768 allows user-assisted remote attackers to execute arbitrary code via a crafted RDZ archive in which the first file has an executable extension.
0
Attacker Value
Unknown
CVE-2007-4751
Disclosure Date: September 18, 2007 (last updated October 04, 2023)
RemoteDocs R-Viewer before 1.6.3768 stores encrypted RDZ file data in unencrypted temporary files, which allows local users to obtain sensitive information by reading the temporary files.
0
Attacker Value
Unknown
CVE-2007-3452
Disclosure Date: June 27, 2007 (last updated October 04, 2023)
SQL injection vulnerability in essentials/minutes/doc.php in eDocStore allows remote attackers to execute arbitrary SQL commands via the doc_id parameter in an inline action.
0
Attacker Value
Unknown
CVE-2006-6545
Disclosure Date: December 14, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in includes/common.php in the ErrorDocs 1.0.0 and earlier module for mxBB (mx_errordocs) allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.
0
Attacker Value
Unknown
CVE-2003-1100
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Hummingbird CyberDOCS 3.5.1, 3.9, and 4.0 allow remote attackers to inject arbitrary web script or HTML via certain vectors.
0
Attacker Value
Unknown
CVE-2003-1101
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Hummingbird CyberDOCS 3.5.1, 3.9, and 4.0 allows remote attackers to obtain the full path of the DM Web Server via invalid login credentials, which reveals the path in an error message.
0
Attacker Value
Unknown
CVE-2003-1103
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
SQL injection vulnerability in loginact.asp for Hummingbird CyberDOCS before 3.9 allows remote attackers to execute arbitrary SQL commands.
0