professional software vulnerabilities
vulnerabilities.aspcode.net
Searching professional software vulnerabilities
Buffer overflow in O'Reilly WebSite Professiona
Professional
|
arbitrary
|
attackers
|
Referrer
|
commands
|
O'Reilly
|
overflow
|
WebSite
|
execute
|
earlier
|
request
|
header
|
Buffer
|
server
|
remote
|
allows
|
long
|
via
|
web
|
GET
|
Buffer overflow in O'Reilly WebSite Professional web server 2.4 and earlier allows remote attackers to execute arbitrary commands via a long GET request or Referrer header.
Directory traversal vulnerability in ASCII NT W
vulnerability
|
Professional
|
WinWrapper
|
attackers
|
Directory
|
traversal
|
arbitrary
|
remote
|
allows
|
files
|
ASCII
|
read
|
via
|
Directory traversal vulnerability in ASCII NT WinWrapper Professional allows remote attackers to read arbitrary files via a .. (dot dot) in the server request.
Microsoft Windows XP Professional upgrade editi
Professional
|
overwrites
|
previously
|
Microsoft
|
installed
|
unpatched
|
Internet
|
Explorer
|
leaving
|
upgrade
|
Windows
|
patches
|
edition
|
Microsoft Windows XP Professional upgrade edition overwrites previously installed patches for Internet Explorer 6.0, leaving Internet Explorer unpatched.
csNewsPro.cgi in CGIScript.net csNews Professio
Professional
|
CGIScriptnet
|
csNewsProcgi
|
csNews
|
csNewsPro.cgi in CGIScript.net csNews Professional (csNewsPro) allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function.
MailWorks Professional allows remote attackers
authentication
|
Professional
|
privileges
|
MailWorks
|
attackers
|
"auth=1"
|
contains
|
"uId=1"
|
cookie
|
bypass
|
remote
|
allows
|
gain
|
via
|
MailWorks Professional allows remote attackers to bypass authentication and gain privileges via a cookie that contains "auth=1" and "uId=1."
Buffer overflow in the IMAP service for MailEna
Enterprise
|
MailEnable
|
overflow
|
service
|
Buffer
|
IMAP
|
Buffer overflow in the IMAP service for MailEnable Enterprise 1.04 and earlier and Professional 1.54 allows remote attackers to execute arbitrary code via a long AUTHENTICATE command.
SQL injection vulnerability in verify.asp for E
vulnerability
|
Professional
|
Guestbook
|
arbitrary
|
attackers
|
parameter
|
verifyasp
|
injection
|
AdminPWD
|
commands
|
execute
|
allows
|
remote
|
Ecomm
|
SQL
|
via
|
SQL injection vulnerability in verify.asp for Ecomm Professional Guestbook 3.x allows remote attackers to execute arbitrary SQL commands via the AdminPWD parameter.
Unknown vulnerability in the HTTPMail service i
vulnerability
|
Professional
|
MailEnable
|
HTTPMail
|
vectors
|
Unknown
|
service
|
attack
|
impact
|
before
|
has
|
Unknown vulnerability in the HTTPMail service in MailEnable Professional before 1.6 has unknown impact and attack vectors.
Unknown vulnerability in the SMTP service in Ma
vulnerability
|
Professional
|
MailEnable
|
attackers
|
Standard
|
Unknown
|
service
|
remote
|
denial
|
before
|
allows
|
cause
|
SMTP
|
Unknown vulnerability in the SMTP service in MailEnable Standard before 1.9 and Professional before 1.6 allows remote attackers to cause a denial of service (crash) during authentication.
Unknown vulnerability in Lasso Professional Ser
vulnerability
|
Professional
|
Server804
|
Unknown
|
Lasso
|
Unknown vulnerability in Lasso Professional Server8.0.4 and 8.0.5 allows attackers to bypass authentication, related to [Auth] tags.
Buffer overflow in the W3C logging for MailEnab
Professional
|
MailEnable
|
Enterprise
|
arbitrary
|
attackers
|
overflow
|
logging
|
execute
|
remote
|
Buffer
|
allows
|
code
|
W3C
|
Buffer overflow in the W3C logging for MailEnable Enterprise 1.1 and Professional 1.6 allows remote attackers to execute arbitrary code.
Multiple unspecified vulnerabilities in MailEna
vulnerabilities
|
Professional
|
unspecified
|
Enterprise
|
MailEnable
|
attackers
|
Multiple
|
service
|
earlier
|
denial
|
allow
|
cause
|
Multiple unspecified vulnerabilities in MailEnable Professional 1.6 and earlier and Enterprise 1.1 and earlier allow attackers to cause a denial of service (crash) via invalid IMAP commands.
Multiple cross-site scripting (XSS) vulnerabili
cross-site
|
scripting
|
Multiple
|
Multiple cross-site scripting (XSS) vulnerabilities in IPswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allow remote attackers to inject arbitrary web script or HTML via the (1) sDeviceView or (2) nDeviceID parameter to (a) NmConsole/Navigation.asp or (3) sHostname parameter to (b) NmConsole/ToolResults.asp.
NmConsole/Login.asp in Ipswitch WhatsUp Profess
NmConsole/Loginasp
|
Professional
|
Ipswitch
|
WhatsUp
|
NmConsole/Login.asp in Ipswitch WhatsUp Professional 2006 and Ipswitch WhatsUp Professional 2006 Premium generates different error messages in a way that allows remote attackers to enumerate valid usernames. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Ipswitch WhatsUp Professional 2006 and Ipswitch
Professional
|
Ipswitch
|
WhatsUp
|
Ipswitch WhatsUp Professional 2006 and Ipswitch WhatsUp Professional 2006 Premium allows remote attackers to obtain full path information via 404 error messages. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
NmConsole/utility/RenderMap.asp in Ipswitch Wha
NmConsole/utility/RenderMapasp
|
Professional
|
Ipswitch
|
WhatsUp
|
NmConsole/utility/RenderMap.asp in Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to obtain sensitive information about network nodes via a modified nDeviceGroupID parameter.
Ipswitch WhatsUp Professional 2006 and WhatsUp
Professional
|
Ipswitch
|
WhatsUp
|
Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to obtain source code for scripts via a trailing dot in a request to NmConsole/Login.asp.
webadmin in MailEnable NetWebAdmin Professional
Professional
|
NetWebAdmin
|
MailEnable
|
webadmin
|
webadmin in MailEnable NetWebAdmin Professional 2.32 and Enterprise 2.32 allows remote attackers to authenticate using an empty password.
CGI-Rescue Shopping Basket Professional 7.50 an
Professional
|
CGI-Rescue
|
Shopping
|
Basket
|
CGI-Rescue Shopping Basket Professional 7.50 and earlier allows remote attackers to inject arbitrary operating system commands via unspecified vectors.
A certain ActiveX control in Morovia Barcode Ac
Professional
|
Morovia
|
Barcode
|
certain
|
ActiveX
|
control
|
A certain ActiveX control in Morovia Barcode ActiveX Professional 3.3.1304 allows remote attackers to overwrite arbitrary files by calling the Save method with an arbitrary filename.
Software vulnerabilities results 1 to 20 of 109
Page:
1
2
3
4
5
6
►