Page 2 of 16 results (0.008 seconds)

CVSS: 6.1EPSS: 0%CPEs: 3EXPL: 1

17 May 2006 — Cross-site scripting (XSS) vulnerability in ftplogin/index.php in Confixx 3.1.2 allows remote attackers to inject arbitrary web script or HTML via the login parameter. • https://www.exploit-db.com/exploits/27884 •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 4

13 Apr 2006 — Cross-site scripting (XSS) vulnerability in allgemein_transfer.php in SWSoft Confixx 3.1.2 allows remote attackers to inject arbitrary web script or HTML via the jahr parameter. • https://www.exploit-db.com/exploits/27623 •

CVSS: 9.8EPSS: 4%CPEs: 3EXPL: 3

13 Apr 2006 — SQL injection vulnerability in index.php in SWSoft Confixx 3.0.6, 3.0.8, and 3.1.2 allows remote attackers to execute arbitrary SQL commands via the SID parameter. • https://www.exploit-db.com/exploits/27628 •

CVSS: 9.8EPSS: 0%CPEs: 3EXPL: 0

26 Apr 2005 — SQL injection vulnerability in Confixx 3.08 and earlier allows remote attackers to execute arbitrary SQL commands via the "change user" field. • http://marc.info/?l=bugtraq&m=111444886429814&w=2 •

CVSS: 6.1EPSS: 1%CPEs: 2EXPL: 2

31 Dec 2004 — Cross-site scripting (XSS) vulnerability in login_up.php3 in Plesk 7.0 and 7.1 Reloaded allows remote attackers to inject arbitrary web script or HTML via the login_name parameter. NOTE: this might be the same vector as CVE-2006-6451. • https://www.exploit-db.com/exploits/24405 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.8EPSS: 7%CPEs: 2EXPL: 3

24 May 2001 — Multiple buffer overflows in s.cgi program in Aspseek search engine 1.03 and earlier allow remote attackers to execute arbitrary commands via (1) a long HTTP query string, or (2) a long tmpl parameter. • https://www.exploit-db.com/exploits/20689 •