Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown
CVE-2023-26107
Disclosure Date: March 06, 2023 (last updated November 08, 2023)
All versions of the package sketchsvg are vulnerable to Arbitrary Code Injection when invoking shell.exec without sanitization nor parametrization while concatenating the current directory as part of the command string.
0
Attacker Value
Unknown
CVE-2014-5611
Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The eBay Kleinanzeigen for Germany (aka com.ebay.kleinanzeigen) application 5.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2010-4211
Disclosure Date: November 09, 2010 (last updated October 04, 2023)
The PayPal app before 3.0.1 for iOS does not verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof a PayPal web server via an arbitrary certificate.
0
Attacker Value
Unknown
CVE-2009-3712
Disclosure Date: October 16, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Ebay Clone 2009 allow remote attackers to execute arbitrary SQL commands via the (1) user_id parameter to feedback.php; and the item_id parameter to (2) view_full_size.php, (3) classifide_ad.php, and (4) crosspromoteitems.php.
0
Attacker Value
Unknown
CVE-2009-2423
Disclosure Date: July 10, 2009 (last updated October 04, 2023)
SQL injection vulnerability in category.php in Ebay Clone 2009 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter in a list action.
0
Attacker Value
Unknown
CVE-2008-2475
Disclosure Date: June 09, 2009 (last updated October 04, 2023)
eBay Enhanced Picture Uploader ActiveX control (EPUWALcontrol.dll) before 1.0.27 allows remote attackers to execute arbitrary commands via the PictureUrls property.
0
Attacker Value
Unknown
CVE-2007-0400
Disclosure Date: January 22, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in admin/memberlist.php in Easebay Resources Login Manager 3.0 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.
0
Attacker Value
Unknown
CVE-2007-0401
Disclosure Date: January 22, 2007 (last updated October 04, 2023)
SQL injection vulnerability in admin/memberlist.php in Easebay Resources Login Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the init_row parameter.
0
Attacker Value
Unknown
CVE-2007-0402
Disclosure Date: January 22, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in admin/edit_member.php in Easebay Resources Paypal Subscription Manager allows remote attackers to inject arbitrary web script or HTML via the username parameter.
0
Attacker Value
Unknown
CVE-2007-0403
Disclosure Date: January 22, 2007 (last updated October 04, 2023)
SQL injection vulnerability in admin/memberlist.php in Easebay Resources Paypal Subscription Manager allows remote attackers to execute arbitrary SQL commands via the keyword parameter.
0