Show filters
84 Total Results
Displaying 61-70 of 84
Sort by:
Attacker Value
Unknown

CVE-2014-4874

Disclosure Date: October 10, 2014 (last updated October 05, 2023)
BMC Track-It! 11.3.0.355 allows remote authenticated users to read arbitrary files by visiting the TrackItWeb/Attachment page.
0
Attacker Value
Unknown

CVE-2014-3800

Disclosure Date: August 07, 2014 (last updated October 05, 2023)
XBMC 13.0 uses world-readable permissions for .xbmc/userdata/sources.xml, which allows local users to obtain user names and passwords by reading this file.
0
Attacker Value
Unknown

CVE-2013-4945

Disclosure Date: July 29, 2013 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to execute arbitrary SQL commands via the (1) ASPSESSIONIDASSRATTQ, (2) TABLE_WIDGET_1, (3) TABLE_WIDGET_2, (4) browserDateTimeInfo, or (5) browserNumberInfo cookie parameter to DashBoardGUI.aspx; or the (6) UID parameter to login.aspx.
0
Attacker Value
Unknown

CVE-2013-4946

Disclosure Date: July 29, 2013 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to inject arbitrary web script or HTML via the (1) SelTab parameter to QV_admin.aspx, the (2) CallBack parameter to QV_grid.aspx, or the (3) HelpPage parameter to commonhelp.aspx.
0
Attacker Value
Unknown

CVE-2012-3842

Disclosure Date: July 03, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in CMD_DOMAIN in JBMC Software DirectAdmin 1.403 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via the (1) select0 or (2) select8 parameters.
0
Attacker Value
Unknown

CVE-2012-2959

Disclosure Date: June 11, 2012 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in password-manager/changePasswords.do in BMC Identity Management Suite 7.5.00.103 allows remote attackers to hijack the authentication of administrators for requests that change passwords.
0
Attacker Value
Unknown

CVE-2011-0975

Disclosure Date: February 10, 2011 (last updated October 04, 2023)
Stack-based buffer overflow in BMC PATROL Agent Service Daemon for in Performance Analysis for Servers, Performance Assurance for Servers, and Performance Assurance for Virtual Servers 7.4.00 through 7.5.10; Performance Analyzer and Performance Predictor for Servers 7.4.00 through 7.5.10; and Capacity Management Essentials 1.2.00 (7.4.15) allows remote attackers to execute arbitrary code via a crafted length value in a BGS_MULTIPLE_READS command to TCP port 6768.
0
Attacker Value
Unknown

CVE-2009-2216

Disclosure Date: June 25, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in CMD_REDIRECT in DirectAdmin 1.33.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the URI in a view=advanced request.
0
Attacker Value
Unknown

CVE-2009-1526

Disclosure Date: May 05, 2009 (last updated October 04, 2023)
JBMC Software DirectAdmin before 1.334 allows local users to create or overwrite any file via a symlink attack on an arbitrary file in a certain temporary directory, related to a request for this temporary file in the PATH_INFO to the CMD_DB script during a backup action.
0
Attacker Value
Unknown

CVE-2009-1525

Disclosure Date: May 05, 2009 (last updated October 04, 2023)
CMD_DB in JBMC Software DirectAdmin before 1.334 allows remote authenticated users to gain privileges via shell metacharacters in the name parameter during a restore action.
0