| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| classifieds.cgi allows remote attackers to read arbitrary files via shell metacharacters. |
| SQL injection vulnerability in topic_post.php in XennoBB 2.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the icon_topic parameter. |
| wwwboard allows a remote attacker to delete message board articles via a malformed argument. |
| PHP remote file inclusion vulnerability in anjel.index.php in ANJEL (formerly MaMML) Component (com_anjel) for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. NOTE: this issue has been disputed by a third party, who says that $mosConfig_absolute_path is set in a configuration file |
| BNBSurvey survey.cgi program allows remote attackers to execute commands via shell metacharacters. |
| BNBForm allows remote attackers to read arbitrary files via the automessage hidden form variable. |
| Mutt mail client allows a remote attacker to execute commands via shell metacharacters. |
| WWWBoard stores encrypted passwords in a password file that is under the web root and thus accessible by remote attackers. |
| WWWBoard has a default username and default password. |
| Multiple PHP remote file inclusion vulnerabilities in NES Game and NES System c108122 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) phphtmllib parameter to (a) phphtmllib/includes.php; tag_utils/ scripts including (b) divtag_utils.php, (c) form_utils.php, (d) html_utils.php, and (e) localinc.php; and widgets/ scripts including (f) FooterNav.php, (g) HTMLPageClass.php, (h) InfoTable.php, (i) localinc.php, (j) NavTable.php, and (k) TextNav.php. |
| HPUX sysdiag allows local users to gain root privileges via a symlink attack during log file creation. |
| FreeBSD mount_union command allows local users to gain root privileges via a symlink attack. |
| The NeXT NetInfo _writers property allows local users to gain root privileges or conduct a denial of service. |
| MajorCool mj_key_cache program allows local users to modify files via a symlink attack. |
| sudo 1.5.x allows local users to execute arbitrary commands via a .. (dot dot) attack. |
| IRIX startmidi program allows local users to modify arbitrary files via a symlink attack. |
| Buffer overflow in HPUX passwd command allows local users to gain root privileges via a command line option. |
| The OmniHTTPD visadmin.exe program allows a remote attacker to conduct a denial of service via a malformed URL which causes a large number of temporary files to be created. |
| Linux kernel before 2.6.15 allows local users to cause a denial of service (panic) via a set_mempolicy call with a 0 bitmask, which causes a panic when a page fault occurs. |
| Race condition in xterm allows local users to modify arbitrary files via the logging option. |