Aggregator
CVE-2024-13020 | code-projects Chat System 1.0 /admin/chatroom.php id sql injection
1 year 5 months ago
A vulnerability classified as critical was found in code-projects Chat System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/chatroom.php. The manipulation of the argument id leads to sql injection.
This vulnerability is known as CVE-2024-13020. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2012-4600 | OTRS up to 3.1.9 cross site scripting (VU#511404 / Nessus ID 74760)
1 year 5 months ago
A vulnerability, which was classified as problematic, was found in OTRS. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2012-4600. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2012-4623 | Cisco IOS up to 12.4/15.2 DHCPv6 input validation (cisco-sa-20120926-dhcpv6 / Nessus ID 62373)
1 year 5 months ago
A vulnerability was found in Cisco IOS up to 12.4/15.2 and classified as critical. Affected by this issue is some unknown functionality of the component DHCPv6 Handler. The manipulation leads to improper input validation.
This vulnerability is handled as CVE-2012-4623. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2012-4617 | Cisco IOS up to 15.2 BGP input validation (cisco-sa-20120926-bgp / Nessus ID 71436)
1 year 5 months ago
A vulnerability was found in Cisco IOS up to 15.2. It has been rated as critical. This issue affects some unknown processing of the component BGP Handler. The manipulation leads to improper input validation.
The identification of this vulnerability is CVE-2012-4617. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2012-4607 | EMC NetWorker up to 8.0.0.1 memory corruption (ID 120873 / XFDB-81113)
1 year 5 months ago
A vulnerability was found in EMC NetWorker up to 8.0.0.1 and classified as very critical. This issue affects some unknown processing. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2012-4607. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2012-4691 | Siemens Automation License Manager up to 5.0 resource management (ssa-783261 / ID 120774)
1 year 5 months ago
A vulnerability was found in Siemens Automation License Manager up to 5.0. It has been classified as problematic. Affected is an unknown function of the component License Manager. The manipulation leads to improper resource management.
This vulnerability is traded as CVE-2012-4691. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2012-4700 | Ecava IntegraXor 3.71/3.72/4.00 ActiveX Control PE3DO32A.ocx memory corruption (ID 120858 / XFDB-81918)
1 year 5 months ago
A vulnerability, which was classified as very critical, has been found in Ecava IntegraXor 3.71/3.72/4.00. Affected by this issue is some unknown functionality of the file PE3DO32A.ocx of the component ActiveX Control. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2012-4700. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2012-4751 | OTRS up to 2.4.13 cross site scripting (VU#603276 / Nessus ID 74831)
1 year 5 months ago
A vulnerability, which was classified as problematic, has been found in OTRS. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2012-4751. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2012-4774 | Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Email File Name Parser code injection (MS12-081 / Nessus ID 63228)
1 year 5 months ago
A vulnerability classified as critical was found in Microsoft Windows 7/Server 2003/Server 2008/Vista/XP. This vulnerability affects unknown code of the component Email File Name Parser. The manipulation leads to code injection.
This vulnerability was named CVE-2012-4774. The attack needs to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2012-4792 | Microsoft Internet Explorer 6/7/8 mshtml.dll CDwnBindInfo resource management (EDB-23785 / Nessus ID 63372)
1 year 5 months ago
A vulnerability classified as critical has been found in Microsoft Internet Explorer 6/7/8. This affects the function CDwnBindInfo in the library mshtml.dll. The manipulation leads to improper resource management.
This vulnerability is uniquely identified as CVE-2012-4792. It is possible to initiate the attack remotely. Furthermore, there is an exploit available. Due to its background and reception, this vulnerability has an historic impact.
A worm is spreading, which is automatically exploiting this vulnerability.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2012-4845 | IBM AIX 6.1/7.1 FTP Server access control (Nessus ID 71163 / ID 120859)
1 year 5 months ago
A vulnerability classified as problematic was found in IBM AIX 6.1/7.1. Affected by this vulnerability is an unknown functionality of the component FTP Server. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2012-4845. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2012-4856 | IBM Power 5 prior 9116-561 credentials management (VU#194604 / ID 120699)
1 year 5 months ago
A vulnerability has been found in IBM Power 5 and classified as very critical. This vulnerability affects unknown code. The manipulation leads to credentials management.
This vulnerability was named CVE-2012-4856. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-7387 | Zoho ManageEngine EventLog Analyzer up to 10.6 event/runQuery.do query sql injection (Exploit 133581 / EDB-38173)
1 year 5 months ago
A vulnerability was found in Zoho ManageEngine EventLog Analyzer up to 10.6. It has been rated as critical. This issue affects some unknown processing of the file event/runQuery.do. The manipulation of the argument query leads to sql injection.
The identification of this vulnerability is CVE-2015-7387. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-0096 | Georgia SoftWorks SSH2 Server up to 7.01.0003 memory corruption (EDB-30971 / XFDB-39360)
1 year 5 months ago
A vulnerability, which was classified as critical, has been found in Georgia SoftWorks SSH2 Server up to 7.01.0003. This issue affects some unknown processing. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2008-0096. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-13039 | code-projects Simple Chat System 1.0 /add_user.php name/email/password/number sql injection
1 year 5 months ago
A vulnerability was found in code-projects Simple Chat System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /add_user.php. The manipulation of the argument name/email/password/number leads to sql injection.
This vulnerability is handled as CVE-2024-13039. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #471644: code-projects.org Simple Chat System V1.0 SQL Injection [Accepted]
1 year 5 months ago
Submit #471644 / VDB-289772
Zwdtk
CVE-2017-1000026 | Chef Software mixlib-archive up to 0.3.0 TAR Archive path traversal (Nessus ID 101857 / ID 176094)
1 year 5 months ago
A vulnerability classified as problematic was found in Chef Software mixlib-archive up to 0.3.0. Affected by this vulnerability is an unknown functionality of the component TAR Archive Handler. The manipulation with the input .. leads to path traversal.
This vulnerability is known as CVE-2017-1000026. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-7174 | Chef Software Chef Manage up to 2.4.4 on Linux User-Account Creation 7pk security (BID-97069 / ID 802343)
1 year 5 months ago
A vulnerability was found in Chef Software Chef Manage up to 2.4.4 on Linux and classified as critical. This issue affects some unknown processing of the component User-Account Creation Handler. The manipulation leads to 7pk security features.
The identification of this vulnerability is CVE-2017-7174. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2016-4326 | Chef Software Chef Manage up to 1.11 on Linux Cookie deserialization (VU#586503)
1 year 5 months ago
A vulnerability was found in Chef Software Chef Manage up to 1.11 on Linux and classified as critical. Affected by this issue is some unknown functionality of the component Cookie Handler. The manipulation leads to deserialization.
This vulnerability is handled as CVE-2016-4326. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com