4 results (0.002 seconds)

CVSS: 9.8EPSS: 2%CPEs: 1EXPL: 2

21 Aug 2006 — PHP remote file inclusion vulnerability in processor/reporter.sql.php in the Reporter Mambo component (com_reporter) allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. Vulnerabilidad de inclusión remota de archivo en PHP en processor/reporter.sql.php en el componente Reporter de Mambo (com_reporter) permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro mosConfig_absolute_path. • https://www.exploit-db.com/exploits/28396 •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

24 May 2005 — templates.admin.users.user_form_processing in Blue Coat Reporter before 7.1.2 allows authenticated users to gain administrator privileges via an HTTP POST that sets volatile.user.administrator to true. • https://www.exploit-db.com/exploits/25697 •

CVSS: 9.1EPSS: 3%CPEs: 1EXPL: 1

24 May 2005 — Unknown vulnerability in Blue Coat Reporter before 7.1.2 allows remote unauthenticated attackers to add a license. • https://www.exploit-db.com/exploits/25698 •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

24 May 2005 — Multiple cross-site scripting (XSS) vulnerabilities in Blue Coat Reporter before 7.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the username in an Add User window or (2) the license key (volatile.license_to_add parameter) in the Licensing page. • http://marc.info/?l=bugtraq&m=111695726810435&w=2 •