Show filters
95 Total Results
Displaying 81-90 of 95
Sort by:
Attacker Value
Unknown
CVE-2015-3415
Disclosure Date: April 24, 2015 (last updated October 05, 2023)
The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a crafted CHECK clause, as demonstrated by CHECK(0&O>O) in a CREATE TABLE statement.
0
Attacker Value
Unknown
CVE-2012-5105
Disclosure Date: September 23, 2012 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in SQLiteManager 1.2.4 allow remote attackers to inject arbitrary web script or HTML via the dbsel parameter to (1) main.php or (2) index.php; or (3) nsextt parameter to index.php.
0
Attacker Value
Unknown
CVE-2011-0995
Disclosure Date: May 13, 2011 (last updated October 04, 2023)
The sqlite3-ruby gem in the rubygem-sqlite3 package before 1.2.4-0.5.1 in SUSE Linux Enterprise (SLE) 11 SP1 uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors.
0
Attacker Value
Unknown
CVE-2010-2095
Disclosure Date: May 27, 2010 (last updated October 04, 2023)
SQL injection vulnerability in index.php in CMSQlite 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the c parameter.
0
Attacker Value
Unknown
CVE-2010-2096
Disclosure Date: May 27, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in CMSQlite 1.2 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod parameter.
0
Attacker Value
Unknown
CVE-2009-4539
Disclosure Date: January 04, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in main.php in SQLiteManager 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the redirect parameter.
0
Attacker Value
Unknown
CVE-2008-6590
Disclosure Date: April 03, 2009 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in LightNEasy "no database" (aka flat) version 1.2.2, and possibly SQLite version 1.2.2, allow remote attackers to read arbitrary files via a .. (dot dot) in the page parameter to (1) index.php and (2) LightNEasy.php.
0
Attacker Value
Unknown
CVE-2008-6592
Disclosure Date: April 03, 2009 (last updated October 04, 2023)
thumbsup.php in Thumbs-Up 1.12, as used in LightNEasy "no database" (aka flat) and SQLite 1.2.2 and earlier, allows remote attackers to copy, rename, and read arbitrary files via directory traversal sequences in the image parameter with a modified cache_dir parameter containing a %00 (encoded null byte).
0
Attacker Value
Unknown
CVE-2008-6589
Disclosure Date: April 03, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in LightNEasy "no database" (aka flat) version 1.2.2, and possibly SQLite version 1.2.2, allow remote attackers to inject arbitrary web script or HTML via the page parameter to (1) index.php and (2) LightNEasy.php.
0
Attacker Value
Unknown
CVE-2008-6593
Disclosure Date: April 03, 2009 (last updated October 04, 2023)
SQL injection vulnerability in LightNEasy/lightneasy.php in LightNEasy SQLite 1.2.2 and earlier allows remote attackers to inject arbitrary PHP code into comments.dat via the dlid parameter to index.php.
0