Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown

CVE-2023-4514

Disclosure Date: November 27, 2023 (last updated November 30, 2023)
The Mmm Simple File List WordPress plugin through 2.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Attacker Value
Unknown

CVE-2023-4297

Disclosure Date: November 27, 2023 (last updated November 30, 2023)
The Mmm Simple File List WordPress plugin through 2.3 does not validate the generated path to list files from, allowing any authenticated users, such as subscribers, to list the content of arbitrary directories.
Attacker Value
Unknown

CVE-2020-12069

Disclosure Date: December 26, 2022 (last updated October 04, 2024)
In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.
Attacker Value
Unknown

CVE-2022-3270

Disclosure Date: December 01, 2022 (last updated November 09, 2023)
In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability.
Attacker Value
Unknown

CVE-2022-3079

Disclosure Date: September 20, 2022 (last updated December 22, 2024)
Festo control block CPX-CEC-C1 and CPX-CMXX in multiple versions allow unauthenticated, remote access to critical webpage functions which may cause a denial of service.
Attacker Value
Unknown

CVE-2022-30311

Disclosure Date: June 08, 2022 (last updated November 29, 2024)
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-refresh-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.
0
Attacker Value
Unknown

CVE-2022-30310

Disclosure Date: June 08, 2022 (last updated November 29, 2024)
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.
0
Attacker Value
Unknown

CVE-2022-30309

Disclosure Date: June 08, 2022 (last updated November 29, 2024)
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.
0
Attacker Value
Unknown

CVE-2022-30308

Disclosure Date: June 08, 2022 (last updated September 17, 2024)
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.
Attacker Value
Unknown

CVE-2014-0760

Disclosure Date: April 25, 2014 (last updated October 05, 2023)
The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion provide an undocumented access method involving the FTP protocol, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
0