Show filters
118 Total Results
Displaying 71-80 of 118
Sort by:
Attacker Value
Unknown

CVE-2008-6911

Disclosure Date: August 06, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the authenticateUser function in includes/authentication.inc.php in BrewBlogger (BB) 2.1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the loginUsername parameter to includes/logincheck.inc.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-6250

Disclosure Date: February 23, 2009 (last updated October 04, 2023)
SQL injection vulnerability in Comdev Web Blogger 4.1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the arcmonth parameter to a blog page.
0
Attacker Value
Unknown

CVE-2008-6180

Disclosure Date: February 19, 2009 (last updated October 04, 2023)
SQL injection vulnerability in system/nlb_user.class.php in NewLife Blogger 3.0 and earlier, and possibly 3.3.1, allows remote attackers to execute arbitrary SQL commands via the nlb3 cookie.
0
Attacker Value
Unknown

CVE-2009-0399

Disclosure Date: February 03, 2009 (last updated October 04, 2023)
Chipmunk Blogger Script allows remote attackers to gain administrator privileges via a direct request to admin/reguser.php. NOTE: this is only a vulnerability when the administrator does not properly follow installation directions.
0
Attacker Value
Unknown

CVE-2009-0403

Disclosure Date: February 03, 2009 (last updated October 04, 2023)
SQL injection vulnerability in admin/authenticate.php in Chipmunk Blogger Script allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
0
Attacker Value
Unknown

CVE-2008-5637

Disclosure Date: December 17, 2008 (last updated October 04, 2023)
SQL injection vulnerability in blog.asp in ParsBlogger (Pb) allows remote attackers to execute arbitrary SQL commands via the wr parameter.
0
Attacker Value
Unknown

CVE-2008-5049

Disclosure Date: November 13, 2008 (last updated October 04, 2023)
Buffer overflow in AKEProtect.sys 3.3.3.0 in ISecSoft Anti-Keylogger Elite 3.3.0 and earlier, and possibly other versions including 3.3.3, allows local users to gain privileges via long inputs to the (1) 0x002224A4, (2) 0x002224C0, and (3) 0x002224CC IOCTL.
0
Attacker Value
Unknown

CVE-2008-3957

Disclosure Date: September 11, 2008 (last updated October 04, 2023)
The Microsoft Windows Image Acquisition Logger ActiveX control allows remote attackers to force the download of arbitrary files onto a client system via a URL in the first argument to the Open method, in conjunction with a full destination pathname in the first argument to the Save method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2008-3563

Disclosure Date: August 10, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Plogger 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the checked array parameter to plog-download.php in an album action and (2) unspecified parameters to plog-remote.php, and (3) allow remote authenticated administrators to execute arbitrary SQL commands via the activate parameter to admin/plog-themes.php, related to theme_dir settings.
0
Attacker Value
Unknown

CVE-2008-3186

Disclosure Date: July 15, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Blog (Blogger) allow remote attackers to inject arbitrary web script or HTML via the membername parameter to (1) members.php, (2) comments.php, (3) photos.php, (4) archive.php, or (5) cat.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0