Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2016-15021
Disclosure Date: January 17, 2023 (last updated October 20, 2023)
A vulnerability was found in nickzren alsdb. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to sql injection. Upgrading to version v2 is able to address this issue. The identifier of the patch is cbc79a68145e845f951113d184b4de207c341599. It is recommended to upgrade the affected component. The identifier VDB-218429 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2018-18875
Disclosure Date: June 18, 2019 (last updated November 27, 2024)
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a stored Cross-site scripting (XSS) vulnerability allows remote authenticated users to inject arbitrary web script via changestationname.php.
0
Attacker Value
Unknown
CVE-2018-18878
Disclosure Date: June 18, 2019 (last updated November 27, 2024)
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, the BACnet daemon does not properly validate input, which could allow a remote attacker to send specially crafted packets causing the device to become unavailable.
0
Attacker Value
Unknown
CVE-2018-18876
Disclosure Date: June 18, 2019 (last updated November 27, 2024)
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a readouts_rd.php directory traversal issue makes it possible to read any file present on the underlying operating system.
0
Attacker Value
Unknown
CVE-2018-18877
Disclosure Date: June 18, 2019 (last updated November 27, 2024)
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can access an alternative configuration page config_main.php that allows manipulation of the device.
0
Attacker Value
Unknown
CVE-2018-18879
Disclosure Date: June 18, 2019 (last updated November 27, 2024)
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to the underlying operating system as user input is not sanitized in networkdiags.php.
0
Attacker Value
Unknown
CVE-2018-18880
Disclosure Date: June 18, 2019 (last updated November 27, 2024)
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a networkdiags.php reflected Cross-site scripting (XSS) vulnerability allows remote authenticated users to inject arbitrary web script.
0
Attacker Value
Unknown
CVE-2006-5594
Disclosure Date: October 27, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in University of British Columbia iPeer 2.0, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: it is possible that this issue is related to CakePHP.
0
Attacker Value
Unknown
CVE-2003-1110
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
The Session Initiation Protocol (SIP) implementation in Columbia SIP User Agent (sipc) 1.74 and other versions before sipc 2.0 build 2003-02-21 allows remote attackers to cause a denial of service or execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.
0