Show filters
33 Total Results
Displaying 1-10 of 33
Sort by:
Attacker Value
Unknown

CVE-2024-8730

Disclosure Date: September 13, 2024 (last updated September 27, 2024)
The Exit Notifier plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.9.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2012-0804

Disclosure Date: May 29, 2012 (last updated October 04, 2023)
Heap-based buffer overflow in the proxy_connect function in src/client.c in CVS 1.11 and 1.12 allows remote HTTP proxy servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTTP response.
0
Attacker Value
Unknown

CVE-2007-2202

Disclosure Date: April 24, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in inc_ACVS/SOAP/Transport.php in Accueil et Conseil en Visites et Sejours Web Services (ACVSWS) PHP5 (ACVSWS_PHP5) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the CheminInclude parameter.
0
Attacker Value
Unknown

CVE-2007-0347

Disclosure Date: January 29, 2007 (last updated October 04, 2023)
The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the "'" (quote) character, which allows remote authenticated users to execute limited SQL injection attacks and cause a denial of service (database error) via a ' character in certain messages, tickets, or Wiki entries.
0
Attacker Value
Unknown

CVE-2005-4831

Disclosure Date: December 31, 2005 (last updated October 04, 2023)
viewcvs in ViewCVS 0.9.2 allows remote attackers to set the Content-Type header to arbitrary values via the content-type parameter, which can be leveraged for cross-site scripting (XSS) and other attacks, as demonstrated using (1) "text/html", or (2) "image/jpeg" with an image that is rendered as HTML by Internet Explorer, a different vulnerability than CVE-2004-1062. NOTE: it was later reported that 0.9.4 is also affected.
0
Attacker Value
Unknown

CVE-2005-4830

Disclosure Date: December 31, 2005 (last updated October 04, 2023)
CRLF injection vulnerability in viewcvs in ViewCVS 0.9.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the content-type parameter.
0
Attacker Value
Unknown

CVE-2005-2693

Disclosure Date: August 26, 2005 (last updated October 04, 2023)
cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack.
0
Attacker Value
Unknown

CVE-2004-1342

Disclosure Date: April 27, 2005 (last updated October 04, 2023)
CVS 1.12 and earlier on Debian GNU/Linux, when using the repouid patch, allows remote attackers to bypass authentication via the pserver access method.
0
Attacker Value
Unknown

CVE-2005-0753

Disclosure Date: April 18, 2005 (last updated October 04, 2023)
Buffer overflow in CVS before 1.11.20 allows remote attackers to execute arbitrary code.
0
Attacker Value
Unknown

CVE-2004-1008

Disclosure Date: January 10, 2005 (last updated October 04, 2023)
Integer signedness error in the ssh2_rdpkt function in PuTTY before 0.56 allows remote attackers to execute arbitrary code via a SSH2_MSG_DEBUG packet with a modified stringlen parameter, which leads to a buffer overflow.
0