Show filters
819 Total Results
Displaying 701-710 of 819
Sort by:
Attacker Value
Unknown
CVE-2008-7076
Disclosure Date: August 25, 2009 (last updated October 04, 2023)
Unrestricted file upload vulnerability in user.modify.profile.php in Kalptaru Infotech Ltd. Star Articles 6.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile photo, then accessing it via a direct request to the file in authorphoto/.
0
Attacker Value
Unknown
CVE-2009-2572
Disclosure Date: July 22, 2009 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in the Fivestar module 5.x-1.x before 5.x-1.14 and 6.x-1.x before 6.x-1.14, a module for Drupal, allows remote attackers to hijack the authentication of arbitrary users for requests that cast votes.
0
Attacker Value
Unknown
CVE-2009-2260
Disclosure Date: June 30, 2009 (last updated October 04, 2023)
stardict 3.0.1, when Enable Net Dict is configured, sends the contents of the clipboard to a dictionary server, which allows remote attackers to obtain sensitive information by sniffing the network.
0
Attacker Value
Unknown
CVE-2009-1657
Disclosure Date: May 18, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in the Starrating plugin before 0.7.7 for b2evolution allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-6539
Disclosure Date: March 30, 2009 (last updated October 04, 2023)
Static code injection vulnerability in user/settings/ in DeStar 0.2.2-5 allows remote authenticated users to add arbitrary administrators and inject arbitrary Python code into destar_cfg.py via a crafted pin parameter.
0
Attacker Value
Unknown
CVE-2008-6538
Disclosure Date: March 30, 2009 (last updated October 04, 2023)
DeStar 0.2.2-5 allows remote attackers to add arbitrary users via a direct request to config/add/CfgOptUser.
0
Attacker Value
Unknown
CVE-2009-1054
Disclosure Date: March 24, 2009 (last updated October 04, 2023)
Unspecified vulnerability in JustSystems Ichitaro 13, 2004 through 2008, Lite2, and Ichitaro viewer 5.1.5.0 and earlier allows remote attackers to execute arbitrary code via a crafted file, as exploited in the wild by Trojan.Tarodrop.H in March 2009.
0
Attacker Value
Unknown
CVE-2008-3074
Disclosure Date: February 21, 2009 (last updated October 04, 2023)
The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (exclamation point) shell metacharacter in (1) the filename of a tar archive and possibly (2) the filename of the first file in a tar archive, which is not properly handled by the VIM TAR plugin (tar.vim) v.10 through v.22, as demonstrated by the shellescape, tarplugin.v2, tarplugin, and tarplugin.updated test cases. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-2712. NOTE: this issue has the same root cause as CVE-2008-3075. NOTE: due to the complexity of the associated disclosures and the incomplete information related to them, there may be inaccuracies in this CVE description and in external mappings to this identifier.
0
Attacker Value
Unknown
CVE-2009-0311
Disclosure Date: January 27, 2009 (last updated October 04, 2023)
The Backbone service (ftbackbone.exe) in EMC AutoStart before 5.3 SP2 allows remote attackers to execute arbitrary code via a packet with a crafted value that is dereferenced as a function pointer.
0
Attacker Value
Unknown
CVE-2008-5874
Disclosure Date: January 08, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php in the (1) com_allhotels or (2) com_5starhotels module. NOTE: some of these details are obtained from third party information.
0