Show filters
92 Total Results
Displaying 81-90 of 92
Sort by:
Attacker Value
Unknown
CVE-2008-1316
Disclosure Date: March 13, 2008 (last updated October 04, 2023)
SQL injection vulnerability in qtf_ind_search_ov.php in QT-cute QuickTalk Forum 1.6 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown
CVE-2007-2956
Disclosure Date: August 13, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in the readRadianceHeader function in (1) src/fileformat/rgbeio.cpp in pfstools 1.6.2 and (2) src/Fileformat/rgbeio.cpp in Qtpfsgui 1.8.11 allows remote attackers to execute arbitrary code via a crafted Radiance RGBE (.hdr) file.
0
Attacker Value
Unknown
CVE-2007-3538
Disclosure Date: July 03, 2007 (last updated October 04, 2023)
SQL injection vulnerability in qtg_msg_view.php in QuickTalk guestbook 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown
CVE-2007-3547
Disclosure Date: July 03, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in qti_checkname.php in QuickTicket 1.2 allows remote attackers to include and execute arbitrary local files a .. (dot dot) in the lang parameter.
0
Attacker Value
Unknown
CVE-2007-3539
Disclosure Date: July 03, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in QuickTicket 1.2 build:20070621 and QuickTalk Forum 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) t and (2) f parameters in (a) qti_ind_post.php and (b) qti_ind_post_prt.php; (3) dir and (4) order parameters in qti_ind_member.php; (5) id parameter in qti_usr.php; and the (6) f parameter in qti_ind_topic.php. NOTE: it was later reported that vector 5 also affects 1.4, 1.5, and 1.5.0.3.
0
Attacker Value
Unknown
CVE-2007-3505
Disclosure Date: July 02, 2007 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in QuickTalk forum 1.3 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) sequence in the lang parameter to (1) qtf_checkname.php, (2) qtf_j_birth.php, or (3) qtf_j_exists.php.
0
Attacker Value
Unknown
CVE-2007-0242
Disclosure Date: April 03, 2007 (last updated October 04, 2023)
The UTF-8 decoder in codecs/qutfcodec.cpp in Qt 3.3.8 and 4.2.3 does not reject long UTF-8 sequences as required by the standard, which allows remote attackers to conduct cross-site scripting (XSS) and directory traversal attacks via long sequences that decode to dangerous metacharacters.
0
Attacker Value
Unknown
CVE-2006-4811
Disclosure Date: October 18, 2006 (last updated October 04, 2023)
Integer overflow in Qt 3.3 before 3.3.7, 4.1 before 4.1.5, and 4.2 before 4.2.1, as used in the KDE khtml library, kdelibs 3.1.3, and possibly other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted pixmap image.
0
Attacker Value
Unknown
CVE-2006-3405
Disclosure Date: July 07, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) delete, (2) pathext, and (3) edit parameters.
0
Attacker Value
Unknown
CVE-2006-3406
Disclosure Date: July 07, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to modify arbitrary files via a .. (dot dot) sequence in the edit parameter.
0