Show filters
97 Total Results
Displaying 71-80 of 97
Sort by:
Attacker Value
Unknown

CVE-2009-2544

Disclosure Date: July 20, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in the Marcelo Costa FileServer component 1.0 for Microsoft Windows Live Messenger and Messenger Plus! Live (MPL) allows remote authenticated users to list arbitrary directories and read arbitrary files via a .. (dot dot) in a pathname.
0
Attacker Value
Unknown

CVE-2008-6667

Disclosure Date: April 08, 2009 (last updated October 04, 2023)
A+ PHP Scripts News Management System (NMS) allows remote attackers to bypass authentication and gain administrator privileges by setting the mobsuser and mobspass cookies to 1.
0
Attacker Value
Unknown

CVE-2008-5366

Disclosure Date: December 08, 2008 (last updated October 04, 2023)
The postinst script in ppp 2.4.4rel on Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/probe-finished or (2) /tmp/ppp-errors temporary file.
0
Attacker Value
Unknown

CVE-2008-5371

Disclosure Date: December 08, 2008 (last updated October 04, 2023)
screenie in screenie 1.30.0 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/.screenie.##### temporary file.
0
Attacker Value
Unknown

CVE-2008-5367

Disclosure Date: December 08, 2008 (last updated October 04, 2023)
ip-up in ppp-udeb 2.4.4rel on Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack on the /tmp/resolv.conf.tmp temporary file.
0
Attacker Value
Unknown

CVE-2008-3668

Disclosure Date: August 13, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Yogurt Social Network module 3.2 rc1 for XOOPS allow remote attackers to inject arbitrary web script or HTML via the uid parameter to (1) friends.php, (2) seutubo.php, (3) album.php, (4) scrapbook.php, (5) index.php, or (6) tribes.php; or (7) the description field of a new scrap.
0
Attacker Value
Unknown

CVE-2008-3191

Disclosure Date: July 16, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in usercp.php in mForum 0.1a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) City, (2) Interest, (3) Email, (4) Icq, (5) msn, or (6) Yahoo Messenger field in an edit_profile action.
0
Attacker Value
Unknown

CVE-2007-6638

Disclosure Date: January 04, 2008 (last updated October 04, 2023)
March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames, passwords, device names, and IP addresses via a direct request for scripts/logfiles.tar.gz.
0
Attacker Value
Unknown

CVE-2007-4532

Disclosure Date: August 25, 2007 (last updated October 04, 2023)
Soldat game server 1.4.2 and earlier, and dedicated server 2.6.2 and earlier, allows remote attackers to cause a denial of service (client lockout) via a series of UDP join packets from a spoofed IP address, which triggers temporary blacklisting of this IP address.
0
Attacker Value
Unknown

CVE-2007-4531

Disclosure Date: August 25, 2007 (last updated October 04, 2023)
Soldat game server 1.4.2 and earlier, and dedicated server 2.6.2 and earlier, allows remote attackers to cause a client denial of service (crash) via (1) a long string to the file transfer port or (2) a long chat message, or (3) a server denial of service (continuous beep and slowdown) via a string containing many 0x07 or other control characters to the file transfer port.
0