Show filters
123 Total Results
Displaying 81-90 of 123
Sort by:
Attacker Value
Unknown

CVE-2009-2884

Disclosure Date: August 20, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in bios.php in PHP Scripts Now World's Tallest Buildings allows remote attackers to inject arbitrary web script or HTML via the rank parameter.
0
Attacker Value
Unknown

CVE-2008-6967

Disclosure Date: August 13, 2009 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in WorldClient in Alt-N MDaemon before 10.02 have unknown impact and attack vectors, probably related to cross-site scripting (XSS) and WorldClient DLL 10.0.1, a different vulnerability than CVE-2008-6893.
0
Attacker Value
Unknown

CVE-2008-6893

Disclosure Date: August 03, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Alt-N MDaemon WorldClient 10.0.2, when Internet Explorer 7 is used, allows remote attackers to inject arbitrary web script or HTML via a crafted img tag.
0
Attacker Value
Unknown

CVE-2008-6698

Disclosure Date: April 10, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in TARGET-E WorldCup Bets (worldcup) 2.0.0 and earlier extension for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
0
Attacker Value
Unknown

CVE-2008-6697

Disclosure Date: April 10, 2009 (last updated October 04, 2023)
SQL injection vulnerability in TARGET-E WorldCup Bets (worldcup) 2.0.0 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
0
Attacker Value
Unknown

CVE-2008-6056

Disclosure Date: February 04, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in World Recipe 2.11 allow remote attackers to inject arbitrary web script or HTML via the (1) n parameter to emailrecipe.aspx, (2) id parameter to recipedetail.aspx, and the (3) catid parameter to validatefieldlength.aspx.
0
Attacker Value
Unknown

CVE-2008-4521

Disclosure Date: October 09, 2008 (last updated October 04, 2023)
SQL injection vulnerability in thisraidprogress.php in the World of Warcraft tracker infusion (raidtracker_panel) module 2.0 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the INFO_RAID_ID parameter.
0
Attacker Value
Unknown

CVE-2008-1755

Disclosure Date: April 11, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in the showSource function in showSource.php in World of Phaos 4.0.1 allows remote attackers to read arbitrary files via directory traversal sequences in the file parameter.
0
Attacker Value
Unknown

CVE-2008-0647

Disclosure Date: February 07, 2008 (last updated October 04, 2023)
Multiple stack-based buffer overflows in the HanGamePluginCn18.HanGamePluginCn18.1 ActiveX control in HanGamePluginCn18.dll in Ourgame GLWorld 2.6.1.29 (aka Lianzong Game Platform) allow remote attackers to execute arbitrary code via long arguments to the (1) hgs_startGame and (2) hgs_startNotify methods, as exploited in the wild as of February 2008. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2007-5711

Disclosure Date: October 30, 2007 (last updated October 04, 2023)
Massive Entertainment World in Conflict 1.001 and earlier allows remote attackers to cause a denial of service (failed assertion and daemon crash) via a large packet to TCP or UDP port 48000.
0