Show filters
97 Total Results
Displaying 81-90 of 97
Sort by:
Attacker Value
Unknown
CVE-2008-4175
Disclosure Date: September 23, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Link Bid Script 1.5 allow remote attackers to execute arbitrary SQL commands via the (1) ucat parameter to upgrade.php and the (2) id parameter to linkadmin/edit.php.
0
Attacker Value
Unknown
CVE-2008-1431
Disclosure Date: March 20, 2008 (last updated October 04, 2023)
RaidSonic NAS-4220-B with 2.6.0-n(2007-10-11) firmware stores a partition encryption key in an unencrypted /system/.crypt file with base64 encoding, which allows local users to obtain the key.
0
Attacker Value
Unknown
CVE-2008-0459
Disclosure Date: January 25, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in update/index.php in Liquid-Silver CMS 0.35, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the update parameter.
0
Attacker Value
Unknown
CVE-2007-6674
Disclosure Date: January 08, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Default.asp in RapidShare Database allows remote attackers to inject arbitrary web script or HTML via the Arayalim parameter.
0
Attacker Value
Unknown
CVE-2007-4208
Disclosure Date: August 08, 2007 (last updated October 04, 2023)
SQL injection vulnerability in default.asp in Next Gen Portfolio Manager allows remote attackers to execute arbitrary SQL commands via the (1) Users_Email or (2) Users_Password parameter in an ExecuteTheLogin action.
0
Attacker Value
Unknown
CVE-2007-3579
Disclosure Date: July 05, 2007 (last updated October 04, 2023)
PHPIDS before 20070703 does not properly handle setting the .text property of a SCRIPT element before its attachment to the DOM, which allows remote attackers to inject arbitrary web script.
0
Attacker Value
Unknown
CVE-2007-3577
Disclosure Date: July 05, 2007 (last updated October 04, 2023)
PHPIDS before 20070703 does not properly handle use of the substr method in (1) document.location.search and (2) document.referrer; (3) certain use of document.location.hash; (4) certain "window[eval" and similar expressions; (5) certain Function expressions; (6) certain '=' expressions, as demonstrated by a 'whatever="something"' sequence; and (7) certain "with" expressions, which allows remote attackers to inject arbitrary web script.
0
Attacker Value
Unknown
CVE-2007-3578
Disclosure Date: July 05, 2007 (last updated October 04, 2023)
PHPIDS before 20070703 does not properly handle (1) arithmetic expressions and (2) unclosed comments, which allows remote attackers to inject arbitrary web script.
0
Attacker Value
Unknown
CVE-2007-3580
Disclosure Date: July 05, 2007 (last updated October 04, 2023)
PHPIDS does not properly handle certain code containing newlines, as demonstrated by a try/catch block within a loop, which allows user-assisted remote attackers to inject arbitrary web script.
0
Attacker Value
Unknown
CVE-2006-5020
Disclosure Date: September 27, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in SolidState 0.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the base_path parameter in manager/pages/ scripts including (1) AccountsPage.class.php, (2) AddInvoicePage.class.php, (3) AddIPAddressPage.class.php, (4) AddPaymentPage.class.php, (5) AddTaxRulePage.class.php, (6) AssignDomainPage.class.php, (7) AssignHostingPage.class.php, (8) AssignProductPage.class.php, (9) BillingPage.class.php, (10) BillingPaymentPage.class.php, (11) BrowseAccountsPage.class.php, (12) BrowseInvoicesPage.class.php, (13) ConfigureEditUserPage.class.php, (14) ConfigureNewUserPage.class.php, (15) ConfigureNewUserReceiptPage.class.php, (16) ConfigureUsersPage.class.php, (17) DeleteAccountPage.class.php, (18) DeleteDomainServicePage.class.php, (19) DeleteHostingServicePage.class.php, (20) DeleteInvoicePage.class.php, (21) DeleteProductPage.class.php, (22) DeleteServerPage.class.php, (23) DomainServicesPage.class.php, (24) Do…
0