Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2009-0963
Disclosure Date: March 19, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in PHPRunner 4.2, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the SearchField parameter to (1) UserView_list.php, (2) orders_list.php, (3) users_list.php, and (4) Administrator_list.php.
0
Attacker Value
Unknown
CVE-2009-0964
Disclosure Date: March 19, 2009 (last updated February 15, 2024)
UserView_list.php in PHPRunner 4.2, and possibly earlier, stores passwords in cleartext in the database, which allows attackers to gain privileges. NOTE: this can be leveraged with a separate SQL injection vulnerability to obtain passwords remotely without authentication.
0
Attacker Value
Unknown
CVE-2006-5956
Disclosure Date: November 17, 2006 (last updated October 04, 2023)
XLineSoft PHPRunner 3.1 stores the (1) database server name, (2) database names, (3) usernames, and (4) passwords in plaintext in %WINDIR%\PHPRunner.ini, which allows local users to obtain sensitive information by reading the file.
0
Attacker Value
Unknown
CVE-2004-2060
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, which is predictable based on table and field names.
0
Attacker Value
Unknown
CVE-2004-2059
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) SearchFor parameter in [TABLE-NAME]_search.asp, (2) SQL parameter in [TABLE-NAME]_edit.asp, (3) SearchFor parameter in [TABLE]_list.asp, or (4) SQL parameter in export.asp.
0
Attacker Value
Unknown
CVE-2004-2058
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
ASPRunner 2.4 allows remote attackers to gain sensitive information via (1) hidden form fields or (2) error messages.
0
Attacker Value
Unknown
CVE-2004-2057
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
SQL injection vulnerability in ASPRunner 2.4 allows remote attackers to execute arbitrary SQL statements.
0