Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown
CVE-2023-29780
Disclosure Date: April 24, 2023 (last updated February 24, 2025)
Third Reality Smart Blind 1.00.54 contains a denial-of-service vulnerability, which allows a remote attacker to send malicious Zigbee messages to a vulnerable device and cause crashes.
0
Attacker Value
Unknown
CVE-2014-9461
Disclosure Date: January 02, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in models/Cart66.php in the Cart66 Lite plugin before 1.5.4 for WordPress allows remote authenticated users to read arbitrary files via a .. (dot dot) in the member_download action to wp-admin/admin-ajax.php.
0
Attacker Value
Unknown
CVE-2014-9442
Disclosure Date: January 02, 2015 (last updated October 05, 2023)
SQL injection vulnerability in models/Cart66Ajax.php in the Cart66 Lite plugin before 1.5.4 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the q parameter in a promotionProductSearch action to wp-admin/admin-ajax.php.
0
Attacker Value
Unknown
CVE-2014-9305
Disclosure Date: December 08, 2014 (last updated October 05, 2023)
SQL injection vulnerability in the shortcodeProductsTable function in models/Cart66Ajax.php in the Cart66 Lite plugin before 1.5.2 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a shortcode_products_table action to wp-admin/admin-ajax.php.
0
Attacker Value
Unknown
CVE-2010-1857
Disclosure Date: May 07, 2010 (last updated October 04, 2023)
SQL injection vulnerability in index.php in RepairShop2 1.9.023 Trial, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the prod parameter in a products.details action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2010-1856
Disclosure Date: May 07, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in RepairShop2 1.9.023 Trial, when magic_quotes_gpc is disabled, allows remote attackers to inject arbitrary web script or HTML via the prod parameter in a products.details action.
0
Attacker Value
Unknown
CVE-2008-0805
Disclosure Date: February 19, 2008 (last updated October 04, 2023)
Unrestricted file upload vulnerability in image.php in PHPizabi 0.848b C1 HFP1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension from the event page, then accessing it via a direct request to the file in system/cache/pictures.
0
Attacker Value
Unknown
CVE-2007-4032
Disclosure Date: July 27, 2007 (last updated October 04, 2023)
Buffer overflow in CrystalPlayer Pro 1.98 allows user-assisted remote attackers to execute arbitrary code via a long string in a .mls Playlist file.
0
Attacker Value
Unknown
CVE-2005-2251
Disclosure Date: July 13, 2005 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in secure.php in PHPSecurePages (phpSP) 0.28beta and earlier allows remote attackers to execute arbitrary code via the cfgProgDir parameter, a variant of CVE-2001-1468.
0
Attacker Value
Unknown
CVE-2003-1175
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in index.php in Sympoll 1.5 allows remote attackers to inject arbitrary web script or HTML via the vo parameter.
0