Show filters
69 Total Results
Displaying 61-69 of 69
Sort by:
Attacker Value
Unknown

CVE-2012-0326

Disclosure Date: March 17, 2012 (last updated October 04, 2023)
The twicca application 0.7.0 through 0.9.30 for Android does not properly restrict the use of network privileges, which allows remote attackers to read media files on an SD card via a crafted application.
0
Attacker Value
Unknown

CVE-2011-2712

Disclosure Date: August 29, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.18, when setAutomaticMultiWindowSupport is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
0
Attacker Value
Unknown

CVE-2010-3208

Disclosure Date: September 03, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in ajax.php in Wiccle Web Builder (WWB) 1.00 and 1.0.1 allows remote attackers to inject arbitrary web script or HTML via the post_text parameter in a site custom_search action to index.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2009-3216

Disclosure Date: September 16, 2009 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in iWiccle 1.01, when magic_quotes_gpc is disabled, allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the show parameter to the admin module, reachable through index.php; or (2) the module parameter to index.php.
0
Attacker Value
Unknown

CVE-2009-3217

Disclosure Date: September 16, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the admin module in iWiccle 1.01 allows remote attackers to execute arbitrary SQL commands via the member_id parameter in an edit_user action to index.php.
0
Attacker Value
Unknown

CVE-2008-6713

Disclosure Date: April 10, 2009 (last updated October 04, 2023)
World in Conflict (WIC) 1.008 and earlier allows remote attackers to cause a denial of service (access violation and crash) via a zero-byte data block to TCP port 48000, which triggers a NULL pointer dereference.
0
Attacker Value
Unknown

CVE-2009-0489

Disclosure Date: February 09, 2009 (last updated October 04, 2023)
The DBus configuration file for Wicd before 1.5.9 allows arbitrary users to own org.wicd.daemon, which allows local users to receive messages that were intended for the Wicd daemon, possibly including credentials.
0
Attacker Value
Unknown

CVE-2007-1097

Disclosure Date: February 26, 2007 (last updated October 04, 2023)
Unrestricted file upload vulnerability in the onAttachFiles function in the upload tool (inc/lib/attachment.lib.php) in Wiclear before 0.11.1 allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors related to filename validation. NOTE: some details were obtained from third party information.
0
Attacker Value
Unknown

CVE-2006-5506

Disclosure Date: October 25, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in WiClear 0.10 allow remote attackers to execute arbitrary PHP code via the path parameter in (1) inc/prepend.inc.php, (2) inc/lib/boxes.lib.php, (3) inc/lib/tools.lib.php, (4) tools/trackback/index.php, and (5) tools/utf8conversion/index.php in admin/; and (6) prepend.inc.php, (7) lib/boxes.lib.php, and (8) lib/history.lib.php in inc/.
0