Show filters
85 Total Results
Displaying 61-70 of 85
Sort by:
Attacker Value
Unknown

CVE-2008-6393

Disclosure Date: March 03, 2009 (last updated October 04, 2023)
PSI Jabber client before 0.12.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file transfer request with a negative value in a SOCKS5 option, which bypasses a signed integer check and triggers an integer overflow and a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2008-6018

Disclosure Date: February 02, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in MyPHPSite, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the mod parameter.
0
Attacker Value
Unknown

CVE-2008-5774

Disclosure Date: December 30, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in ASPSiteWare HomeBuilder 1.0 and 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) iType parameter to (a) type.asp and (b) type2.asp and the (2) iPro parameter to (c) detail.asp.
0
Attacker Value
Unknown

CVE-2008-5772

Disclosure Date: December 30, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in ASPSiteWare RealtyListings 1.0 and 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) iType parameter to type.asp and the (2) iPro parameter to detail.asp.
0
Attacker Value
Unknown

CVE-2008-3598

Disclosure Date: August 12, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in psipuss 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the Cid parameter to categories.php or (2) the Username parameter to login.php.
0
Attacker Value
Unknown

CVE-2007-5918

Disclosure Date: November 10, 2007 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in edit.php in the MS TopSites add-on for PHP-Nuke does not verify that the uname parameter matches the current account, which allows remote authenticated users to change arbitrary accounts or change the SiteTitleName field as an arbitrary user via a modified uname value in an edit action to modules.php.
0
Attacker Value
Unknown

CVE-2007-4881

Disclosure Date: September 14, 2007 (last updated October 04, 2023)
SQL injection vulnerability in profile/myprofile.php in psi-labs.com social networking script (psisns), probably 1.0, allows remote attackers to execute arbitrary SQL commands via the u parameter.
0
Attacker Value
Unknown

CVE-2007-2199

Disclosure Date: April 24, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vincent Blavet PhpConcept Library, as used in multiple products including (1) Joomla! 1.5.0 Beta, (2) N/X Web Content Management System (WCMS) 4.5, (3) CJG EXPLORER PRO 3.3, and (4) phpSiteBackup 0.1, allows remote attackers to execute arbitrary PHP code via a URL in the g_pcltar_lib_dir parameter.
0
Attacker Value
Unknown

CVE-2007-1650

Disclosure Date: March 24, 2007 (last updated October 04, 2023)
pcapsipdump.cpp in pcapsipdump before 0.1.3 allows remote attackers to cause a denial of service (application crash) via a malformed SIP packet, which results in a NULL pointer dereference.
0
Attacker Value
Unknown

CVE-2007-0950

Disclosure Date: February 15, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in listmain.asp in Fullaspsite ASP Hosting Site allows remote attackers to inject arbitrary web script or HTML via the cat parameter.
0