Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown

CVE-2023-26107

Disclosure Date: March 06, 2023 (last updated November 08, 2023)
All versions of the package sketchsvg are vulnerable to Arbitrary Code Injection when invoking shell.exec without sanitization nor parametrization while concatenating the current directory as part of the command string.
Attacker Value
Unknown

CVE-2014-5611

Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The eBay Kleinanzeigen for Germany (aka com.ebay.kleinanzeigen) application 5.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2010-4211

Disclosure Date: November 09, 2010 (last updated October 04, 2023)
The PayPal app before 3.0.1 for iOS does not verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof a PayPal web server via an arbitrary certificate.
0
Attacker Value
Unknown

CVE-2009-3712

Disclosure Date: October 16, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Ebay Clone 2009 allow remote attackers to execute arbitrary SQL commands via the (1) user_id parameter to feedback.php; and the item_id parameter to (2) view_full_size.php, (3) classifide_ad.php, and (4) crosspromoteitems.php.
0
Attacker Value
Unknown

CVE-2009-2423

Disclosure Date: July 10, 2009 (last updated October 04, 2023)
SQL injection vulnerability in category.php in Ebay Clone 2009 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter in a list action.
0
Attacker Value
Unknown

CVE-2008-2475

Disclosure Date: June 09, 2009 (last updated October 04, 2023)
eBay Enhanced Picture Uploader ActiveX control (EPUWALcontrol.dll) before 1.0.27 allows remote attackers to execute arbitrary commands via the PictureUrls property.
0
Attacker Value
Unknown

CVE-2007-0400

Disclosure Date: January 22, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in admin/memberlist.php in Easebay Resources Login Manager 3.0 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.
0
Attacker Value
Unknown

CVE-2007-0401

Disclosure Date: January 22, 2007 (last updated October 04, 2023)
SQL injection vulnerability in admin/memberlist.php in Easebay Resources Login Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the init_row parameter.
0
Attacker Value
Unknown

CVE-2007-0402

Disclosure Date: January 22, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in admin/edit_member.php in Easebay Resources Paypal Subscription Manager allows remote attackers to inject arbitrary web script or HTML via the username parameter.
0
Attacker Value
Unknown

CVE-2007-0403

Disclosure Date: January 22, 2007 (last updated October 04, 2023)
SQL injection vulnerability in admin/memberlist.php in Easebay Resources Paypal Subscription Manager allows remote attackers to execute arbitrary SQL commands via the keyword parameter.
0