Show filters
73 Total Results
Displaying 71-73 of 73
Sort by:
Attacker Value
Unknown

CVE-2007-0518

Disclosure Date: January 26, 2007 (last updated October 04, 2023)
Scriptsez Smart PHP Subscriber (aka subscribe) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain encoded passwords via a direct request for pwd.txt.
0
Attacker Value
Unknown

CVE-2006-1961

Disclosure Date: April 21, 2006 (last updated October 04, 2023)
Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13, Hosting Solution Engine (HSE) and User Registration Tool (URT) before 20060419, and all versions of Ethernet Subscriber Solution Engine (ESSE) and CiscoWorks2000 Service Management Solution (SMS) allow local users to gain Linux shell access via shell metacharacters in arguments to the "show" command in the application's command line interface (CLI), aka bug ID CSCsd21502 (WLSE), CSCsd22861 (URT), and CSCsd22859 (HSE). NOTE: other issues might be addressed by the Cisco advisory.
0
Attacker Value
Unknown

CVE-2005-4794

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Cisco IP Phones 7902/7905/7912, ATA 186/188, Unity Express, ACNS, and Subscriber Edge Services Manager (SESM) allows remote attackers to cause a denial of service (crash or instability) via a compressed DNS packet with a label length byte with an incorrect offset.
0