Page 2 of 14 results (0.005 seconds)

CVSS: 7.8EPSS: 0%CPEs: 7EXPL: 4

27 Jan 2017 — The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access to the man account to gain privileges via vectors involving insecure chown use. Las tareas de limpieza diarias mandb en Man-db en versiones anteriores a la 2.7.6.1-1 tal y como se distribuye en Ubuntu y Debian permiten que usuarios locales con acceso a la cuenta "man" ganen privilegios mediante vectores que implican el uso inseguro de la función chown. It was discovered that man-db incorrec... • https://packetstorm.news/files/id/140759 • CWE-284: Improper Access Control •

CVSS: 9.8EPSS: 9%CPEs: 1EXPL: 1

27 Feb 2007 — JBrowser allows remote attackers to bypass authentication and access certain administrative capabilities via a direct request for _admin/. JBrowser permite a atacantes remotos evitar la validación y acceder a ciertas capacidades administrativas a través de una respuesta directa para _admin/. • https://www.exploit-db.com/exploits/23628 •

CVSS: 6.1EPSS: 36%CPEs: 1EXPL: 2

19 Jul 2005 — Multiple cross-site scripting (XSS) vulnerabilities in Simple Message Board Version 2.0 Beta 1 allow remote attackers to inject arbitrary web script or HTML via the (1) FID parameter to forum.cfm, (2) UID parameter to user.cfm, (3) TID parameter to thread.cfm, or (4) PostDate parameter to search.cfm. Múltiples vulnerabilidades de secuencia de comandos en sitios cruzados en Simple Message Board Version 2.0 Beta 1 permite que atacantes remtos inyecten script web arbitrario o HTML mediante 1) el parámetro FID ... • http://marc.info/?l=bugtraq&m=112137585701087&w=2 •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

20 Dec 1999 — DNS PRO allows remote attackers to conduct a denial of service via a large number of connections. • https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-2000-0020 •