Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown
CVE-2025-22363
Disclosure Date: January 07, 2025 (last updated January 08, 2025)
Missing Authorization vulnerability in ORION Allada T-shirt Designer for Woocommerce.This issue affects Allada T-shirt Designer for Woocommerce: from n/a through 1.1.
0
Attacker Value
Unknown
CVE-2024-3072
Disclosure Date: April 30, 2024 (last updated January 05, 2025)
The ACF Front End Editor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_texts() function in all versions up to, and including, 2.0.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary post title, content, and ACF data.
0
Attacker Value
Unknown
CVE-2022-46856
Disclosure Date: May 25, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in ORION Woocommerce Products Designer plugin <= 4.3.3 versions.
0
Attacker Value
Unknown
CVE-2022-31793
Disclosure Date: August 04, 2022 (last updated February 24, 2025)
do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single character before a desired path on the filesystem. This occurs because the code skips over the first character when serving files. Arris NVG443, NVG599, NVG589, and NVG510 devices and Arris-derived BGW210 and BGW320 devices are affected.
0
Attacker Value
Unknown
CVE-2018-20999
Disclosure Date: August 26, 2019 (last updated November 27, 2024)
An issue was discovered in the orion crate before 0.11.2 for Rust. reset() calls cause incorrect results.
0
Attacker Value
Unknown
CVE-2015-8355
Disclosure Date: August 24, 2017 (last updated November 26, 2024)
Multiple SQL injection vulnerabilities in the orion.extfeedbackform module before 2.1.3 for Bitrix allow remote authenticated users to execute arbitrary SQL commands via the (1) order or (2) "by" parameter to admin/orion.extfeedbackform_efbf_forms.php.
0
Attacker Value
Unknown
CVE-2009-4493
Disclosure Date: January 13, 2010 (last updated October 04, 2023)
Orion Application Server 2.0.7 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.
0
Attacker Value
Unknown
CVE-2008-0959
Disclosure Date: May 29, 2008 (last updated October 04, 2023)
Multiple stack-based buffer overflows in the Online Media Technologies NCTSoft NCTAudioInformation2 ActiveX control in NCTAudioInformation2.dll, as used in (1) Power Audio CD Grabber 1.0, (2) Power Audio CD Burner 1.02, (3) CinematicMP3 1.4.0.0, (4) Alive MP3 WAV Converter 3.9.3.2, and possibly other products, allow remote attackers to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown
CVE-2007-1471
Disclosure Date: March 16, 2007 (last updated October 04, 2023)
admin/default.asp in Orion-Blog 2.0 allows remote attackers to bypass authentication controls and gain privileges via a direct URL request for admin/AdminBlogNewsEdit.asp.
0
Attacker Value
Unknown
CVE-2006-0816
Disclosure Date: March 24, 2006 (last updated February 22, 2025)
Orion Application Server before 2.0.7, when running on Windows, allows remote attackers to obtain the source code of JSP files via (1) . (dot) and (2) space characters in the extension of a URL.
0