Show filters
97 Total Results
Displaying 81-90 of 97
Sort by:
Attacker Value
Unknown
CVE-2008-6901
Disclosure Date: August 06, 2009 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in 2532designs 2532|Gigs 1.2.2 Stable, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter to (1) settings.php, (2) deleteuser.php, (3) mini_calendar.php, (4) manage_venues.php, and (5) manage_gigs.php, a different vector than CVE-2007-4585.
0
Attacker Value
Unknown
CVE-2009-2639
Disclosure Date: July 28, 2009 (last updated October 04, 2023)
SQL injection vulnerability in admin.php in MRCGIGUY The Ticket System 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewticket action.
0
Attacker Value
Unknown
CVE-2009-2080
Disclosure Date: June 16, 2009 (last updated October 04, 2023)
admin.php in MRCGIGUY The Ticket System 2.0 does not properly restrict access, which allows remote attackers to (1) obtain sensitive configuration information via the editconfig action or (2) change the administrator's password via the id parameter in an editop action.
0
Attacker Value
Unknown
CVE-2009-0726
Disclosure Date: February 24, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the gigcal_gigs_id parameter in a details action to index.php.
0
Attacker Value
Unknown
CVE-2009-0730
Disclosure Date: February 24, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla!, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the gigcal _venues_id parameter in a details action to index.php, which is not properly handled by venuedetails.php, and (2) the gigcal_bands_id parameter in a details action to index.php, which is not properly handled by banddetails.php, different vectors than CVE-2009-0726.
0
Attacker Value
Unknown
CVE-2008-6199
Disclosure Date: February 20, 2009 (last updated October 04, 2023)
2532designs 2532|Gigs 1.2.2 and earlier allows remote attackers to trigger a backup and obtain sensitive information via a direct request to backup.php, which creates backup.sql under the web root with insufficient access control.
0
Attacker Value
Unknown
CVE-2007-4585
Disclosure Date: August 29, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in activateuser.php in 2532|Gigs 1.2.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.
0
Attacker Value
Unknown
CVE-2006-7119
Disclosure Date: March 06, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in kernel/system/startup.php in J. He PHPGiggle 12.08 and earlier, as distributed on comscripts.com, allows remote attackers to execute arbitrary PHP code via a URL in the CFG_PHPGIGGLE_ROOT parameter.
0
Attacker Value
Unknown
CVE-2006-7086
Disclosure Date: March 02, 2007 (last updated October 04, 2023)
The (1) dlback.php and (2) dlback.cgi scripts in Hot Links allow remote attackers to obtain sensitive information and download the database via a direct request with a modified dl parameter.
0
Attacker Value
Unknown
CVE-2006-4499
Disclosure Date: August 31, 2006 (last updated October 04, 2023)
ModernBill 5.0.4 and earlier uses cURL with insecure settings for CURLOPT_SSL_VERIFYPEER and CURLOPT_SSL_VERIFYHOST that do not verify SSL certificates, which allows remote attackers to read network traffic via a man-in-the-middle (MITM) attack.
0