Show filters
72 Total Results
Displaying 61-70 of 72
Sort by:
Attacker Value
Unknown

CVE-2012-5225

Disclosure Date: October 01, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in webscr.php in xClick Cart 1.0.1 and 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the shopping_url parameter.
0
Attacker Value
Unknown

CVE-2012-3372

Disclosure Date: July 09, 2012 (last updated November 08, 2023)
The default configuration of Cyberoam UTM appliances uses the same Certification Authority certificate and same private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the presence of the Cyberoam_SSL_CA certificate in a list of trusted root certification authorities. NOTE: the vendor disputes the significance of this issue because the appliance "does not allow import or export of the foresaid private key.
0
Attacker Value
Unknown

CVE-2011-5050

Disclosure Date: January 04, 2012 (last updated October 04, 2023)
SQL injection vulnerability in corporate/Controller in Elitecore Technologies Cyberoam UTM before 10.01.2 build 059 allows remote authenticated administrators to execute arbitrary SQL commands via the tableid parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2010-5016

Disclosure Date: November 02, 2011 (last updated October 04, 2023)
SQL injection vulnerability in matchdb.php in Elite Gaming Ladders 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the match parameter.
0
Attacker Value
Unknown

CVE-2010-5014

Disclosure Date: November 02, 2011 (last updated October 04, 2023)
SQL injection vulnerability in standings.php in Elite Gaming Ladders 3.5 allows remote attackers to execute arbitrary SQL commands via the ladder[id] parameter.
0
Attacker Value
Unknown

CVE-2010-5017

Disclosure Date: November 02, 2011 (last updated October 04, 2023)
SQL injection vulnerability in stats.php in Elite Gaming Ladders 3.0 allows remote attackers to execute arbitrary SQL commands via the account parameter.
0
Attacker Value
Unknown

CVE-2009-3314

Disclosure Date: September 23, 2009 (last updated October 04, 2023)
SQL injection vulnerability in ladders.php in Elite Gaming Ladders 3.2 allows remote attackers to execute arbitrary SQL commands via the platform parameter.
0
Attacker Value
Unknown

CVE-2008-4046

Disclosure Date: September 11, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in eliteCMS 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.
0
Attacker Value
Unknown

CVE-2007-3975

Disclosure Date: July 25, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in Elite Forum 1.0.0.0 allows remote attackers to inject arbitrary web script or HTML via the title parameter in a ptopic action, a different vulnerability than CVE-2005-3412.
0
Attacker Value
Unknown

CVE-2007-3591

Disclosure Date: July 06, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Profile.php in Elite Bulletin Board before 1.0.10 allows remote attackers to modify profile information via unspecified vectors related to "a remote form," probably related to direct requests and missing authorization checks.
0