Show filters
140 Total Results
Displaying 61-70 of 140
Sort by:
Attacker Value
Unknown
CVE-2010-4369
Disclosure Date: December 02, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in AWStats before 7.0 allows remote attackers to have an unspecified impact via a crafted LoadPlugin directory.
0
Attacker Value
Unknown
CVE-2010-4367
Disclosure Date: December 02, 2010 (last updated October 04, 2023)
awstats.cgi in AWStats before 7.0 accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located on a (1) WebDAV server or (2) NFS server.
0
Attacker Value
Unknown
CVE-2009-5020
Disclosure Date: December 02, 2010 (last updated October 04, 2023)
Open redirect vulnerability in awredir.pl in AWStats before 6.95 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
0
Attacker Value
Unknown
CVE-2010-4368
Disclosure Date: December 02, 2010 (last updated October 04, 2023)
awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located at a UNC share pathname.
0
Attacker Value
Unknown
CVE-2010-1512
Disclosure Date: May 17, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in aria2 before 1.9.3 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file.
0
Attacker Value
Unknown
CVE-2003-1584
Disclosure Date: February 05, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in SurfStats allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
0
Attacker Value
Unknown
CVE-2009-3617
Disclosure Date: October 20, 2009 (last updated November 08, 2023)
Format string vulnerability in the AbstractCommand::onAbort function in src/AbstractCommand.cc in aria2 before 1.6.2, when logging is enabled, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a download URI. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2009-3575
Disclosure Date: October 07, 2009 (last updated October 04, 2023)
Buffer overflow in DHTRoutingTableDeserializer.cc in aria2 0.15.3, 1.2.0, and other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.
0
Attacker Value
Unknown
CVE-2009-2143
Disclosure Date: June 22, 2009 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in firestats-wordpress.php in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the fs_javascript parameter.
0
Attacker Value
Unknown
CVE-2009-2144
Disclosure Date: June 22, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0