Show filters
78 Total Results
Displaying 71-78 of 78
Sort by:
Attacker Value
Unknown

CVE-2014-9401

Disclosure Date: December 31, 2014 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the WP Limit Posts Automatically plugin 0.7 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the lpa_post_letters parameter in the wp-limit-posts-automatically.php page to wp-admin/options-general.php.
0
Attacker Value
Unknown

CVE-2012-5659

Disclosure Date: March 12, 2013 (last updated October 05, 2023)
Untrusted search path vulnerability in plugins/abrt-action-install-debuginfo-to-abrt-cache.c in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to load and execute arbitrary Python modules by modifying the PYTHONPATH environment variable to reference a malicious Python module.
0
Attacker Value
Unknown

CVE-2012-5660

Disclosure Date: March 12, 2013 (last updated October 05, 2023)
abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to set world-writable permissions for arbitrary files and possibly gain privileges via a symlink attack on "the directories used to store information about crashes."
0
Attacker Value
Unknown

CVE-2012-1106

Disclosure Date: July 03, 2012 (last updated October 04, 2023)
The C handler plug-in in Automatic Bug Reporting Tool (ABRT), possibly 2.0.8 and earlier, does not properly set the group (GID) permissions on core dump files for setuid programs when the sysctl fs.suid_dumpable option is set to 2, which allows local users to obtain sensitive information.
0
Attacker Value
Unknown

CVE-2009-4777

Disclosure Date: April 21, 2010 (last updated October 04, 2023)
Unspecified vulnerability in multiple versions of Hitachi JP1/Automatic Job Management System 2 - View, JP1/Integrated Management - View, and JP1/Cm2/SNMP System Observer, allows remote attackers to cause a denial of service ("abnormal" termination) via vectors related to the display of an "invalid GIF file."
0
Attacker Value
Unknown

CVE-2008-6960

Disclosure Date: August 12, 2009 (last updated October 04, 2023)
download.php in X10media x10 Automatic Mp3 Search Engine Script 1.5.5 through 1.6 allows remote attackers to read arbitrary files via an encoded url parameter, as demonstrated by obtaining database credentials from includes/constants.php.
0
Attacker Value
Unknown

CVE-2008-4141

Disclosure Date: September 24, 2008 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in x10Media x10 Automatic MP3 Script 1.5.5 allow remote attackers to execute arbitrary PHP code via a URL in the web_root parameter to (1) includes/function_core.php and (2) templates/layout_lyrics.php.
0
Attacker Value
Unknown

CVE-2006-2068

Disclosure Date: April 27, 2006 (last updated October 04, 2023)
Unspecified vulnerability in Hitachi JP1 products allow remote attackers to cause a denial of service (application stop or fail) via unexpected requests or data.
0