Show filters
97 Total Results
Displaying 81-90 of 97
Sort by:
Attacker Value
Unknown

CVE-2008-4175

Disclosure Date: September 23, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Link Bid Script 1.5 allow remote attackers to execute arbitrary SQL commands via the (1) ucat parameter to upgrade.php and the (2) id parameter to linkadmin/edit.php.
0
Attacker Value
Unknown

CVE-2008-1431

Disclosure Date: March 20, 2008 (last updated October 04, 2023)
RaidSonic NAS-4220-B with 2.6.0-n(2007-10-11) firmware stores a partition encryption key in an unencrypted /system/.crypt file with base64 encoding, which allows local users to obtain the key.
0
Attacker Value
Unknown

CVE-2008-0459

Disclosure Date: January 25, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in update/index.php in Liquid-Silver CMS 0.35, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the update parameter.
0
Attacker Value
Unknown

CVE-2007-6674

Disclosure Date: January 08, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Default.asp in RapidShare Database allows remote attackers to inject arbitrary web script or HTML via the Arayalim parameter.
0
Attacker Value
Unknown

CVE-2007-4208

Disclosure Date: August 08, 2007 (last updated October 04, 2023)
SQL injection vulnerability in default.asp in Next Gen Portfolio Manager allows remote attackers to execute arbitrary SQL commands via the (1) Users_Email or (2) Users_Password parameter in an ExecuteTheLogin action.
0
Attacker Value
Unknown

CVE-2007-3579

Disclosure Date: July 05, 2007 (last updated October 04, 2023)
PHPIDS before 20070703 does not properly handle setting the .text property of a SCRIPT element before its attachment to the DOM, which allows remote attackers to inject arbitrary web script.
0
Attacker Value
Unknown

CVE-2007-3577

Disclosure Date: July 05, 2007 (last updated October 04, 2023)
PHPIDS before 20070703 does not properly handle use of the substr method in (1) document.location.search and (2) document.referrer; (3) certain use of document.location.hash; (4) certain "window[eval" and similar expressions; (5) certain Function expressions; (6) certain '=' expressions, as demonstrated by a 'whatever="something"' sequence; and (7) certain "with" expressions, which allows remote attackers to inject arbitrary web script.
0
Attacker Value
Unknown

CVE-2007-3578

Disclosure Date: July 05, 2007 (last updated October 04, 2023)
PHPIDS before 20070703 does not properly handle (1) arithmetic expressions and (2) unclosed comments, which allows remote attackers to inject arbitrary web script.
0
Attacker Value
Unknown

CVE-2007-3580

Disclosure Date: July 05, 2007 (last updated October 04, 2023)
PHPIDS does not properly handle certain code containing newlines, as demonstrated by a try/catch block within a loop, which allows user-assisted remote attackers to inject arbitrary web script.
0
Attacker Value
Unknown

CVE-2006-5020

Disclosure Date: September 27, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in SolidState 0.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the base_path parameter in manager/pages/ scripts including (1) AccountsPage.class.php, (2) AddInvoicePage.class.php, (3) AddIPAddressPage.class.php, (4) AddPaymentPage.class.php, (5) AddTaxRulePage.class.php, (6) AssignDomainPage.class.php, (7) AssignHostingPage.class.php, (8) AssignProductPage.class.php, (9) BillingPage.class.php, (10) BillingPaymentPage.class.php, (11) BrowseAccountsPage.class.php, (12) BrowseInvoicesPage.class.php, (13) ConfigureEditUserPage.class.php, (14) ConfigureNewUserPage.class.php, (15) ConfigureNewUserReceiptPage.class.php, (16) ConfigureUsersPage.class.php, (17) DeleteAccountPage.class.php, (18) DeleteDomainServicePage.class.php, (19) DeleteHostingServicePage.class.php, (20) DeleteInvoicePage.class.php, (21) DeleteProductPage.class.php, (22) DeleteServerPage.class.php, (23) DomainServicesPage.class.php, (24) Do…
0