Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2020-23977

Disclosure Date: August 27, 2020 (last updated February 22, 2025)
KandNconcepts Club CMS 1.1 and 1.2 has cross site scripting via the 'team.php,player.php,club.php' id parameter.
Attacker Value
Unknown

CVE-2020-23973

Disclosure Date: August 27, 2020 (last updated February 22, 2025)
KandNconcepts Club CMS 1.1 and 1.2 has SQL Injection via the 'team.php,player.php,club.php' id parameter.
Attacker Value
Unknown

CVE-2013-0662

Disclosure Date: April 01, 2014 (last updated October 05, 2023)
Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow remote attackers to execute arbitrary code via a large buffer-size value in a Modbus Application Header.
0
Attacker Value
Unknown

CVE-2011-3720

Disclosure Date: September 23, 2011 (last updated October 04, 2023)
conceptcms 5.3.1, 5.3.3, and possibly other versions allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by sys_libs/umlib/um_authserver.inc.php and certain other files.
0
Attacker Value
Unknown

CVE-2007-2660

Disclosure Date: May 14, 2007 (last updated November 08, 2023)
PHP remote file inclusion vulnerability in pcltrace.lib.php in the PclTar module in Vincent Blavet PhpConcept Library, as used in CJG EXPLORER PRO 3.3 and earlier and probably other products, allows remote attackers to execute arbitrary PHP code via a URL in the g_pcltar_lib_dir parameter. NOTE: CVE disputes this issue since there is no include statement in pcltrace.lib.php. NOTE: the pcltar.lib.php vector is already covered by CVE-2007-2199
0