Show filters
735 Total Results
Displaying 641-650 of 735
Sort by:
Attacker Value
Unknown

CVE-2008-5642

Disclosure Date: December 17, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in admin/login.php in CMS Made Simple 1.4.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a cms_language cookie.
0
Attacker Value
Unknown

CVE-2008-4811

Disclosure Date: October 31, 2008 (last updated October 04, 2023)
The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 r2797 and earlier allows remote attackers to execute arbitrary PHP code via vectors related to templates and a \ (backslash) before a dollar-sign character.
0
Attacker Value
Unknown

CVE-2008-4810

Disclosure Date: October 31, 2008 (last updated October 04, 2023)
The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 before r2797 allows remote attackers to execute arbitrary PHP code via vectors related to templates and (1) a dollar-sign character, aka "php executed in templates;" and (2) a double quoted literal string, aka a "function injection security hole." NOTE: each vector affects slightly different SVN revisions.
0
Attacker Value
Unknown

CVE-2008-4351

Disclosure Date: September 30, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in phpSmartCom 0.2 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the p parameter.
0
Attacker Value
Unknown

CVE-2008-4352

Disclosure Date: September 30, 2008 (last updated October 04, 2023)
SQL injection vulnerability in inc/pages/viewprofile.php in phpSmartCom 0.2 allows remote attackers to execute arbitrary SQL commands via the uid parameter in a viewprofile action to index.php.
0
Attacker Value
Unknown

CVE-2008-3767

Disclosure Date: August 22, 2008 (last updated October 04, 2023)
SQL injection vulnerability in classified.php in phpBazar 2.0.2 allows remote attackers to execute arbitrary SQL commands via the adid parameter.
0
Attacker Value
Unknown

CVE-2008-2234

Disclosure Date: August 18, 2008 (last updated October 04, 2023)
Multiple buffer overflows in Openwsman 1.2.0 and 2.0.0 allow remote attackers to execute arbitrary code via a crafted "Authorization: Basic" HTTP header.
0
Attacker Value
Unknown

CVE-2008-2233

Disclosure Date: August 18, 2008 (last updated October 04, 2023)
The client in Openwsman 1.2.0 and 2.0.0, in unknown configurations, allows remote Openwsman servers to replay SSL sessions via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-3134

Disclosure Date: July 10, 2008 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory consumption) via (a) unspecified vectors in the (1) AVI, (2) AVS, (3) DCM, (4) EPT, (5) FITS, (6) MTV, (7) PALM, (8) RLA, and (9) TGA decoder readers; and (b) the GetImageCharacteristics function in magick/image.c, as reachable from a crafted (10) PNG, (11) JPEG, (12) BMP, or (13) TIFF file.
0
Attacker Value
Unknown

CVE-2008-1854

Disclosure Date: April 16, 2008 (last updated October 04, 2023)
Unspecified vulnerability in SmarterMail Web Server (SMWebSvr.exe) in SmarterMail 5.0.2999 allows remote attackers to cause a denial of service (service termination) via a long HTTP (1) GET, (2) HEAD, (3) PUT, (4) POST, or (5) TRACE request. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0