Show filters
97 Total Results
Displaying 71-80 of 97
Sort by:
Attacker Value
Unknown
CVE-2011-3815
Disclosure Date: September 24, 2011 (last updated October 04, 2023)
WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by js/calendar.php and certain other files.
0
Attacker Value
Unknown
CVE-2011-3781
Disclosure Date: September 24, 2011 (last updated October 04, 2023)
PHPIDS 0.6.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tests/IDS/VersionTest.php and certain other files.
0
Attacker Value
Unknown
CVE-2010-0751
Disclosure Date: April 06, 2010 (last updated October 04, 2023)
The ip_evictor function in ip_fragment.c in libnids before 1.24, as used in dsniff and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via crafted fragmented packets.
0
Attacker Value
Unknown
CVE-2009-4198
Disclosure Date: December 04, 2009 (last updated October 04, 2023)
SQL injection vulnerability in my_orders.php in MyMiniBill allows remote authenticated users to execute arbitrary SQL commands via the orderid parameter in a status action.
0
Attacker Value
Unknown
CVE-2008-7117
Disclosure Date: August 28, 2009 (last updated October 04, 2023)
eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) files via a certain request with the file parameter set to style.css. NOTE: this can probably be leveraged for cross-site scripting (XSS) attacks.
0
Attacker Value
Unknown
CVE-2008-7118
Disclosure Date: August 28, 2009 (last updated October 04, 2023)
WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain SQL query logs via a direct request for logs/cron.log.
0
Attacker Value
Unknown
CVE-2008-7116
Disclosure Date: August 28, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the admin panel (admin/) in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the username.
0
Attacker Value
Unknown
CVE-2008-7119
Disclosure Date: August 28, 2009 (last updated October 04, 2023)
SQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown
CVE-2008-7081
Disclosure Date: August 25, 2009 (last updated October 04, 2023)
userHandler.cgi in RaidSonic ICY BOX NAS firmware 2.3.2.IB.2.RS.1 allows remote attackers to bypass authentication and gain administrator privileges by setting the login parameter to admin. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2008-4763
Disclosure Date: October 28, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in sample.php in WiKID wClient-PHP 3.0-2 and earlier allow remote attackers to inject arbitrary web script or HTML via the PHP_SELF variable.
0