Show filters
97 Total Results
Displaying 61-70 of 97
Sort by:
Attacker Value
Unknown

CVE-2011-2647

Disclosure Date: August 23, 2011 (last updated October 04, 2023)
Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted archive name in the list of testdrive modified files.
0
Attacker Value
Unknown

CVE-2010-4791

Disclosure Date: April 27, 2011 (last updated October 04, 2023)
SQL injection vulnerability in infusions/mg_user_fotoalbum_panel/mg_user_fotoalbum.php in the MG User-Fotoalbum (mg_user_fotoalbum_panel) module 1.0.1 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the album_id parameter.
0
Attacker Value
Unknown

CVE-2010-1326

Disclosure Date: September 15, 2010 (last updated October 04, 2023)
perms.cpp in March Hare Software CVSNT 2.0.58, 2.5.01, 2.5.02, 2.5.03 before build 3736, 2.5.04 before build 2862; CVS Suite 2.5.03, 2008 before build 3736, and 2009 before 3729 allows remote attackers to bypass the permissions check, modify arbitrary modules and directories within CVSROOT, and execute arbitrary code via a crafted branch name ACL, possibly related to incorrect inheritance.
0
Attacker Value
Unknown

CVE-2010-1022

Disclosure Date: March 19, 2010 (last updated October 04, 2023)
The TYPO3 Security - Salted user password hashes (t3sec_saltedpw) extension before 0.2.13 for TYPO3 allows remote attackers to bypass authentication via unspecified vectors.
0
Attacker Value
Unknown

CVE-2009-4359

Disclosure Date: December 20, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in folder.php in the SmartMedia 0.85 Beta module for XOOPS allows remote attackers to inject arbitrary web script or HTML via the categoryid parameter.
0
Attacker Value
Unknown

CVE-2009-3515

Disclosure Date: October 01, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in dnet_admin/index.php in d.net CMS allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the type parameter.
0
Attacker Value
Unknown

CVE-2009-3514

Disclosure Date: October 01, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in d.net CMS allow remote attackers to execute arbitrary SQL commands via (1) the page parameter to index.php; and allow remote authenticated administrators to execute arbitrary SQL commands via the (2) edit_id and (3) _p parameter in a news action to dnet_admin/index.php.
0
Attacker Value
Unknown

CVE-2008-6909

Disclosure Date: August 06, 2009 (last updated October 04, 2023)
Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not sign all required data in requests, which has unspecified impact, probably related to man-in-the-middle attacks that modify critical data and allow remote attackers to impersonate other users and gain privileges.
0
Attacker Value
Unknown

CVE-2008-6910

Disclosure Date: August 06, 2009 (last updated October 04, 2023)
Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not use timeouts for signed requests, which allows remote attackers to impersonate other users and gain privileges via a replay attack that sends the same request.
0
Attacker Value
Unknown

CVE-2008-6908

Disclosure Date: August 06, 2009 (last updated October 04, 2023)
Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, uses an insecure hash when signing requests, which allows remote attackers to impersonate other users and gain privileges.
0