sl 5500 software vulnerabilities
vulnerabilities.aspcode.net
Searching sl 5500 software vulnerabilities
WatchGuard ServerLock for Windows 2000 before S
ServerLock
|
WatchGuard
|
Windows
|
WatchGuard ServerLock for Windows 2000 before SL 2.0.3 allows local users to load arbitrary modules via the OpenProcess() function, as demonstrated using (1) a DLL injection attack, (2) ZwSetSystemInformation, and (3) API hooking in OpenProcess.
Stack-based buffer overflows in SL Mail Pro 2.0
Stack-based
|
overflows
|
buffer
|
Mail
|
Pro
|
Stack-based buffer overflows in SL Mail Pro 2.0.9 allow remote attackers to execute arbitrary code via (1) user.dll, (2) loadpageadmin.dll or (3) loadpageuser.dll.
Attack Mitigator IPS 5500 3.11.008, and possibl
Mitigator
|
Attack
|
IPS
|
Attack Mitigator IPS 5500 3.11.008, and possibly other versions, when configured in a one-armed routing configuration, allows remote attackers to cause a denial of service (CPU consumption) via a large number of HTTP requests.
SQL injection vulnerability in PhotoPost PHP Pr
vulnerability
|
PhotoPost
|
arbitrary
|
injection
|
attackers
|
commands
|
execute
|
remote
|
allow
|
via
|
PHP
|
SQL
|
may
|
Pro
|
SQL injection vulnerability in PhotoPost PHP Pro 5.x may allow remote attackers to execute arbitrary SQL commands via (1) the sl parameter to showmembers.php or (2) the photo parameter to showphoto.php.
SQL injection vulnerability in page.php in SL_s
vulnerability
|
arbitrary
|
attackers
|
parameter
|
injection
|
commands
|
execute
|
pagephp
|
SL_site
|
id_page
|
allows
|
remote
|
SQL
|
via
|
SQL injection vulnerability in page.php in SL_site 1.0 allows remote attackers to execute arbitrary SQL commands via the id_page parameter. NOTE: this issue could be used to produce resultant XSS from an error message.
Directory traversal vulnerability in gallerie.p
admin/configincphp
|
vulnerability
|
directories
|
galleriephp
|
construct
|
arbitrary
|
parameter
|
sequences
|
attackers
|
Directory
|
traversal
|
SL_site
|
allows
|
images
|
remote
|
which
|
list
|
used
|
name
|
via
|
rep
|
Directory traversal vulnerability in gallerie.php in SL_site 1.0 allows remote attackers to list images in arbitrary directories via ".." sequences in the rep parameter, which is used to construct a directory name in admin/config.inc.php. NOTE: this issue could be used to produce resultant XSS from an error message.
Cross-site scripting (XSS) vulnerability in SL_
Cross-site
|
scripting
|
Cross-site scripting (XSS) vulnerability in SL_site 1.0 allows remote attackers to inject arbitrary web script or HTML via the recherche parameter in recherche.php. NOTE: other XSS vectors, as reported in the original disclosure, are resultant from other primary vulnerabilities that have separate CVE names.
Multiple cross-site scripting (XSS) vulnerabili
cross-site
|
scripting
|
Multiple
|
Multiple cross-site scripting (XSS) vulnerabilities in the WebVPN feature in the Cisco VPN 3000 Series Concentrators and Cisco ASA 5500 Series Adaptive Security Appliances (ASA), when in WebVPN clientless mode, allow remote attackers to inject arbitrary web script or HTML via the domain parameter in (1) dnserror.html and (2) connecterror.html, aka bugid CSCsd81095 (VPN3k) and CSCse48193 (ASA). NOTE: the vendor states that "WebVPN full-network-access mode" is not affected, despite the claims by the original researcher.
Cisco PIX 500 Series Security Appliances and AS
Cisco
|
PIX
|
Cisco PIX 500 Series Security Appliances and ASA 5500 Series Adaptive Security Appliances, when running 7.0(x) up to 7.0(5) and 7.1(x) up to 7.1(2.4), and Firewall Services Module (FWSM) 3.1(x) up to 3.1(1.6), causes the EXEC password, local user passwords, and the enable password to be changed to a "non-random value" under certain circumstances, which causes administrators to be locked out and might allow attackers to gain access.
PHP remote file inclusion vulnerability in admi
admin/editeur/spaw_controlclassphp
|
vulnerability
|
parameter
|
attackers
|
spaw_root
|
arbitrary
|
inclusion
|
Provence
|
execute
|
earlier
|
SL_Site
|
remote
|
allows
|
code
|
file
|
Web
|
PHP
|
via
|
URL
|
PHP remote file inclusion vulnerability in admin/editeur/spaw_control.class.php in Web Provence SL_Site 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: CVE analysis suggests that this issue is actually in a third party product, SPAW Editor PHP Edition.
PHP remote file inclusion vulnerability in incl
includes/logincphp
|
vulnerability
|
Guestbook
|
inclusion
|
SignKorn
|
Telekorn
|
remote
|
file
|
PHP
|
PHP remote file inclusion vulnerability in includes/log.inc.php in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_globals is enabled and _SESSION[permission] parameter is set to "yes", allows remote attackers to execute arbitrary PHP code via a URL in the dir_path parameter.
Multiple PHP remote file inclusion vulnerabilit
vulnerabilities
|
inclusion
|
Guestbook
|
Telekorn
|
SignKorn
|
Multiple
|
remote
|
file
|
PHP
|
Multiple PHP remote file inclusion vulnerabilities in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the dir_path parameter in (1) index.php, (2) includes/functions.gb.php, (3) includes/functions.admin.php, (4) includes/admin.inc.php, (5) help.php, (6) smile.php, (7) entry.php; (8) adminhelp0.php, (9) adminhelp1.php, (10) adminhelp2.php, and (11) adminhelp3.php in (a) help/en and (b) help/de directories; and the (12) preview.php, (13) log.php, (14) index.php, (15) config.php, and (16) admin.php in the (c) admin directory, a different set of vectors than CVE-2006-4788.
Cisco PIX 500 and ASA 5500 Series Security Appl
Cisco
|
PIX
|
Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to inspect certain TCP-based protocols, allows remote attackers to cause a denial of service (device reboot) via malformed TCP packets.
Unspecified vulnerability in Cisco PIX 500 and
vulnerability
|
Unspecified
|
Cisco
|
PIX
|
Unspecified vulnerability in Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to use the LOCAL authentication method, allows remote authenticated users to gain privileges via unspecified vectors.
Cisco PIX 500 and ASA 5500 Series Security Appl
Cisco
|
PIX
|
Cisco PIX 500 and ASA 5500 Series Security Appliances 6.x before 6.3(5.115), 7.0 before 7.0(5.2), and 7.1 before 7.1(2.5), and the FWSM 3.x before 3.1(3.24), when the "inspect sip" option is enabled, allows remote attackers to cause a denial of service (device reboot) via malformed SIP packets.
Cisco PIX 500 and ASA 5500 Series Security Appl
Cisco
|
PIX
|
Cisco PIX 500 and ASA 5500 Series Security Appliances 7.0 before 7.0(4.14) and 7.1 before 7.1(2.1), and the FWSM 2.x before 2.3(4.12) and 3.x before 3.1(3.24), when "inspect http" is enabled, allows remote attackers to cause a denial of service (device reboot) via malformed HTTP traffic.
Multiple PHP remote file inclusion vulnerabilit
sl_theme_unix_path
|
vulnerabilities
|
Streamline
|
inclusion
|
parameter
|
arbitrary
|
attackers
|
10-beta4
|
Multiple
|
execute
|
remote
|
Server
|
Media
|
allow
|
code
|
file
|
PHP
|
via
|
URL
|
Multiple PHP remote file inclusion vulnerabilities in Streamline PHP Media Server 1.0-beta4 allow remote attackers to execute arbitrary PHP code via a URL in the sl_theme_unix_path parameter to (1) admin_footer.php, (2) info_footer.php, (3) theme_footer.php, (4) browse_footer.php, (5) account_footer.php, or (6) search_footer.php in core/theme/includes/. NOTE: the vulnerability is present only when the administrator does not follow installation instructions about the requirement for .htaccess Limit support.
Software vulnerabilities results 1 to 18 of 18
Page:
1