Show filters
92 Total Results
Displaying 81-90 of 92
Sort by:
Attacker Value
Unknown

CVE-2008-1316

Disclosure Date: March 13, 2008 (last updated October 04, 2023)
SQL injection vulnerability in qtf_ind_search_ov.php in QT-cute QuickTalk Forum 1.6 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2007-2956

Disclosure Date: August 13, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in the readRadianceHeader function in (1) src/fileformat/rgbeio.cpp in pfstools 1.6.2 and (2) src/Fileformat/rgbeio.cpp in Qtpfsgui 1.8.11 allows remote attackers to execute arbitrary code via a crafted Radiance RGBE (.hdr) file.
0
Attacker Value
Unknown

CVE-2007-3538

Disclosure Date: July 03, 2007 (last updated October 04, 2023)
SQL injection vulnerability in qtg_msg_view.php in QuickTalk guestbook 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2007-3547

Disclosure Date: July 03, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in qti_checkname.php in QuickTicket 1.2 allows remote attackers to include and execute arbitrary local files a .. (dot dot) in the lang parameter.
0
Attacker Value
Unknown

CVE-2007-3539

Disclosure Date: July 03, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in QuickTicket 1.2 build:20070621 and QuickTalk Forum 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) t and (2) f parameters in (a) qti_ind_post.php and (b) qti_ind_post_prt.php; (3) dir and (4) order parameters in qti_ind_member.php; (5) id parameter in qti_usr.php; and the (6) f parameter in qti_ind_topic.php. NOTE: it was later reported that vector 5 also affects 1.4, 1.5, and 1.5.0.3.
0
Attacker Value
Unknown

CVE-2007-3505

Disclosure Date: July 02, 2007 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in QuickTalk forum 1.3 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) sequence in the lang parameter to (1) qtf_checkname.php, (2) qtf_j_birth.php, or (3) qtf_j_exists.php.
0
Attacker Value
Unknown

CVE-2007-0242

Disclosure Date: April 03, 2007 (last updated October 04, 2023)
The UTF-8 decoder in codecs/qutfcodec.cpp in Qt 3.3.8 and 4.2.3 does not reject long UTF-8 sequences as required by the standard, which allows remote attackers to conduct cross-site scripting (XSS) and directory traversal attacks via long sequences that decode to dangerous metacharacters.
0
Attacker Value
Unknown

CVE-2006-4811

Disclosure Date: October 18, 2006 (last updated October 04, 2023)
Integer overflow in Qt 3.3 before 3.3.7, 4.1 before 4.1.5, and 4.2 before 4.2.1, as used in the KDE khtml library, kdelibs 3.1.3, and possibly other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted pixmap image.
0
Attacker Value
Unknown

CVE-2006-3405

Disclosure Date: July 07, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) delete, (2) pathext, and (3) edit parameters.
0
Attacker Value
Unknown

CVE-2006-3406

Disclosure Date: July 07, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to modify arbitrary files via a .. (dot dot) sequence in the edit parameter.
0