Show filters
95 Total Results
Displaying 81-90 of 95
Sort by:
Attacker Value
Unknown

CVE-2015-3415

Disclosure Date: April 24, 2015 (last updated October 05, 2023)
The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a crafted CHECK clause, as demonstrated by CHECK(0&O>O) in a CREATE TABLE statement.
0
Attacker Value
Unknown

CVE-2012-5105

Disclosure Date: September 23, 2012 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in SQLiteManager 1.2.4 allow remote attackers to inject arbitrary web script or HTML via the dbsel parameter to (1) main.php or (2) index.php; or (3) nsextt parameter to index.php.
0
Attacker Value
Unknown

CVE-2011-0995

Disclosure Date: May 13, 2011 (last updated October 04, 2023)
The sqlite3-ruby gem in the rubygem-sqlite3 package before 1.2.4-0.5.1 in SUSE Linux Enterprise (SLE) 11 SP1 uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors.
0
Attacker Value
Unknown

CVE-2010-2095

Disclosure Date: May 27, 2010 (last updated October 04, 2023)
SQL injection vulnerability in index.php in CMSQlite 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the c parameter.
0
Attacker Value
Unknown

CVE-2010-2096

Disclosure Date: May 27, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in CMSQlite 1.2 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod parameter.
0
Attacker Value
Unknown

CVE-2009-4539

Disclosure Date: January 04, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in main.php in SQLiteManager 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the redirect parameter.
0
Attacker Value
Unknown

CVE-2008-6590

Disclosure Date: April 03, 2009 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in LightNEasy "no database" (aka flat) version 1.2.2, and possibly SQLite version 1.2.2, allow remote attackers to read arbitrary files via a .. (dot dot) in the page parameter to (1) index.php and (2) LightNEasy.php.
0
Attacker Value
Unknown

CVE-2008-6592

Disclosure Date: April 03, 2009 (last updated October 04, 2023)
thumbsup.php in Thumbs-Up 1.12, as used in LightNEasy "no database" (aka flat) and SQLite 1.2.2 and earlier, allows remote attackers to copy, rename, and read arbitrary files via directory traversal sequences in the image parameter with a modified cache_dir parameter containing a %00 (encoded null byte).
0
Attacker Value
Unknown

CVE-2008-6589

Disclosure Date: April 03, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in LightNEasy "no database" (aka flat) version 1.2.2, and possibly SQLite version 1.2.2, allow remote attackers to inject arbitrary web script or HTML via the page parameter to (1) index.php and (2) LightNEasy.php.
0
Attacker Value
Unknown

CVE-2008-6593

Disclosure Date: April 03, 2009 (last updated October 04, 2023)
SQL injection vulnerability in LightNEasy/lightneasy.php in LightNEasy SQLite 1.2.2 and earlier allows remote attackers to inject arbitrary PHP code into comments.dat via the dlid parameter to index.php.
0