Show filters
77 Total Results
Displaying 71-77 of 77
Sort by:
Attacker Value
Unknown
CVE-2017-6551
Disclosure Date: May 02, 2017 (last updated November 26, 2024)
Pexip Infinity before 14.2 allows remote attackers to cause a denial of service (service restart) or execute arbitrary code via vectors related to Conferencing Nodes.
0
Attacker Value
Unknown
CVE-2014-8779
Disclosure Date: February 03, 2015 (last updated October 05, 2023)
Pexip Infinity before 8 uses the same SSH host keys across different customers' installations, which allows man-in-the-middle attackers to spoof Management and Conferencing Nodes by leveraging these keys.
0
Attacker Value
Unknown
CVE-2009-3949
Disclosure Date: November 16, 2009 (last updated October 04, 2023)
cp/profile.php in VivaPrograms Infinity 2.0.5 and earlier does not require administrative authentication for the donewauthor action, which allows remote attackers to create administrative accounts via the name, password, and conf_password parameters.
0
Attacker Value
Unknown
CVE-2009-3212
Disclosure Date: September 16, 2009 (last updated October 04, 2023)
SQL injection vulnerability in VivaPrograms Infinity Script 2.x.x, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username field.
0
Attacker Value
Unknown
CVE-2009-3211
Disclosure Date: September 16, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in VivaPrograms Infinity Script 2.x.x, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the options[style_dir] parameter to the default URI.
0
Attacker Value
Unknown
CVE-2006-6269
Disclosure Date: December 04, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Infinitytechs Restaurants CM allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in rating.asp, (2) the mealid parameter in meal_rest.asp, and (3) the resid parameter in res_details.asp.
0
Attacker Value
Unknown
CVE-2004-0625
Disclosure Date: December 06, 2004 (last updated February 22, 2025)
SQL injection vulnerability in Infinity WEB 1.0 allows remote attackers to bypass authentication and gain privileges via the login page.
0