Show filters
89 Total Results
Displaying 61-70 of 89
Sort by:
Attacker Value
Unknown

CVE-2014-1693

Disclosure Date: December 08, 2014 (last updated October 05, 2023)
Multiple CRLF injection vulnerabilities in the FTP module in Erlang/OTP R15B03 allow context-dependent attackers to inject arbitrary FTP commands via CRLF sequences in the (1) user, (2) account, (3) cd, (4) ls, (5) nlist, (6) rename, (7) delete, (8) mkdir, (9) rmdir, (10) recv, (11) recv_bin, (12) recv_chunk_start, (13) send, (14) send_bin, (15) send_chunk_start, (16) append_chunk_start, (17) append, or (18) append_bin command.
0
Attacker Value
Unknown

CVE-2012-5702

Disclosure Date: October 21, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) callback parameter in a color_selector action, (2) field parameter in a date_format action, or (3) company_name parameter in an addedit action to index.php. NOTE: the date parameter vector is already covered by CVE-2008-3886.
0
Attacker Value
Unknown

CVE-2012-5701

Disclosure Date: October 20, 2014 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in dotProject before 2.1.7 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search_string or (2) where parameter in a contacts action, (3) dept_id parameter in a departments action, (4) project_id[] parameter in a project action, or (5) company_id parameter in a system action to index.php. NOTE: this can be leveraged using CSRF to allow remote attackers to execute arbitrary SQL commands.
0
Attacker Value
Unknown

CVE-2011-3729

Disclosure Date: September 23, 2011 (last updated October 04, 2023)
dotproject 2.1.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by style/dp-grey-theme/footer.php and certain other files.
0
Attacker Value
Unknown

CVE-2011-0766

Disclosure Date: May 31, 2011 (last updated October 04, 2023)
The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14B03, uses predictable seeds based on the current time, which makes it easier for remote attackers to guess DSA host and SSH session keys.
0
Attacker Value
Unknown

CVE-2008-7230

Disclosure Date: September 14, 2009 (last updated October 04, 2023)
Unspecified vulnerability in Small Footprint CIM Broker (SFCB) before 1.2.5 has unknown impact and attack vectors.
0
Attacker Value
Unknown

CVE-2008-7158

Disclosure Date: September 02, 2009 (last updated October 04, 2023)
Numara FootPrints 7.5a through 7.5a1 and 8.0 through 8.0a allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) transcriptFile parameter to MRcgi/MRchat.pl or (2) LOADFILE parameter to MRcgi/MRABLoad2.pl. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-6747

Disclosure Date: April 23, 2009 (last updated October 04, 2023)
dotProject before 2.1.2 does not properly restrict access to administrative pages, which allows remote attackers to gain privileges. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2009-0109

Disclosure Date: January 09, 2009 (last updated October 04, 2023)
SQL injection vulnerability in index.php in RiotPix 0.61 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2009-0110

Disclosure Date: January 09, 2009 (last updated October 04, 2023)
SQL injection vulnerability in read.php in RiotPix 0.61 and earlier allows remote attackers to execute arbitrary SQL commands via the forumid parameter.
0