Show filters
735 Total Results
Displaying 621-630 of 735
Sort by:
Attacker Value
Unknown

CVE-2009-4995

Disclosure Date: August 25, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in frmTickets.aspx in SmarterTools SmarterTrack before 4.0.3504 allows remote attackers to inject arbitrary web script or HTML via the email address field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2010-3099

Disclosure Date: August 20, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in SmartSoft Ltd SmartFTP Client 4.0.1124.0, and possibly other versions before 4.0 Build 1133, allows remote FTP servers to overwrite arbitrary files via a "..\" (dot dot backslash) in a filename. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2010-2315

Disclosure Date: June 17, 2010 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in picturelib.php in SmartISoft phpBazar 2.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the cat parameter.
0
Attacker Value
Unknown

CVE-2010-1482

Disclosure Date: May 12, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in admin/editprefs.php in the backend in CMS Made Simple (CMSMS) before 1.7.1 might allow remote attackers to inject arbitrary web script or HTML via the date_format_string parameter.
0
Attacker Value
Unknown

CVE-2010-1271

Disclosure Date: April 06, 2010 (last updated October 04, 2023)
SQL injection vulnerability in showplugs.php in smartplugs 1.3 allows remote attackers to execute arbitrary SQL commands via the domain parameter.
0
Attacker Value
Unknown

CVE-2010-0947

Disclosure Date: March 10, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in post.aspx in Max Network Technology BBSMAX 3.0, 4.1, and 4.2 allows remote attackers to inject arbitrary web script or HTML via the action parameter.
0
Attacker Value
Unknown

CVE-2009-4340

Disclosure Date: December 17, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the No indexed Search (no_indexed_search) extension 0.2.0 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2009-4341

Disclosure Date: December 17, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the No indexed Search (no_indexed_search) extension 0.2.0 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
0
Attacker Value
Unknown

CVE-2009-4221

Disclosure Date: December 07, 2009 (last updated October 04, 2023)
SQL injection vulnerability in classified.php in phpBazar 2.1.1fix and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter, a different vector than CVE-2008-3767.
0
Attacker Value
Unknown

CVE-2009-4222

Disclosure Date: December 07, 2009 (last updated October 04, 2023)
phpBazar 2.1.1fix and earlier does not require administrative authentication for admin/admin.php, which allows remote attackers to obtain access to the admin control panel via a direct request.
0