Show filters
77 Total Results
Displaying 71-77 of 77
Sort by:
Attacker Value
Unknown

CVE-2017-6551

Disclosure Date: May 02, 2017 (last updated November 26, 2024)
Pexip Infinity before 14.2 allows remote attackers to cause a denial of service (service restart) or execute arbitrary code via vectors related to Conferencing Nodes.
0
Attacker Value
Unknown

CVE-2014-8779

Disclosure Date: February 03, 2015 (last updated October 05, 2023)
Pexip Infinity before 8 uses the same SSH host keys across different customers' installations, which allows man-in-the-middle attackers to spoof Management and Conferencing Nodes by leveraging these keys.
0
Attacker Value
Unknown

CVE-2009-3949

Disclosure Date: November 16, 2009 (last updated October 04, 2023)
cp/profile.php in VivaPrograms Infinity 2.0.5 and earlier does not require administrative authentication for the donewauthor action, which allows remote attackers to create administrative accounts via the name, password, and conf_password parameters.
0
Attacker Value
Unknown

CVE-2009-3212

Disclosure Date: September 16, 2009 (last updated October 04, 2023)
SQL injection vulnerability in VivaPrograms Infinity Script 2.x.x, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username field.
0
Attacker Value
Unknown

CVE-2009-3211

Disclosure Date: September 16, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in VivaPrograms Infinity Script 2.x.x, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the options[style_dir] parameter to the default URI.
0
Attacker Value
Unknown

CVE-2006-6269

Disclosure Date: December 04, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Infinitytechs Restaurants CM allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in rating.asp, (2) the mealid parameter in meal_rest.asp, and (3) the resid parameter in res_details.asp.
0
Attacker Value
Unknown

CVE-2004-0625

Disclosure Date: December 06, 2004 (last updated February 22, 2025)
SQL injection vulnerability in Infinity WEB 1.0 allows remote attackers to bypass authentication and gain privileges via the login page.
0