Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown

CVE-2024-8568

Disclosure Date: September 08, 2024 (last updated September 17, 2024)
A vulnerability, which was classified as critical, was found in Mini-Tmall up to 20240901. Affected is the function rewardMapper.select of the file tmall/admin/order/1/1. The manipulation of the argument orderBy leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2023-50630

Disclosure Date: January 04, 2024 (last updated January 11, 2024)
Cross Site Scripting (XSS) vulnerability in xiweicheng TMS v.2.28.0 allows a remote attacker to execute arbitrary code via a crafted script to the click here function.
Attacker Value
Unknown

CVE-2021-30134

Disclosure Date: December 26, 2022 (last updated February 24, 2025)
php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php.
Attacker Value
Unknown

CVE-2022-26247

Disclosure Date: March 20, 2022 (last updated February 23, 2025)
TMS v2.28.0 contains an insecure permissions vulnerability via the component /TMS/admin/user/Update2. This vulnerability allows attackers to modify the administrator account and password.
Attacker Value
Unknown

CVE-2015-5704

Disclosure Date: September 25, 2017 (last updated November 26, 2024)
scripts/licensecheck.pl in devscripts before 2.15.7 allows local users to execute arbitrary shell commands.
0
Attacker Value
Unknown

CVE-2015-5705

Disclosure Date: September 06, 2017 (last updated November 26, 2024)
Argument injection vulnerability in devscripts before 2.15.7 allows remote attackers to write to arbitrary files via a crafted symlink and crafted filename.
0
Attacker Value
Unknown

CVE-2015-5471

Disclosure Date: January 12, 2016 (last updated November 25, 2024)
Absolute path traversal vulnerability in include/user/download.php in the Swim Team plugin 1.44.10777 for WordPress allows remote attackers to read arbitrary files via a full pathname in the file parameter.
0
Attacker Value
Unknown

CVE-2013-0348

Disclosure Date: December 13, 2013 (last updated October 05, 2023)
thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allows local users to obtain sensitive information by reading the file.
0
Attacker Value
Unknown

CVE-2012-0958

Disclosure Date: December 26, 2012 (last updated October 05, 2023)
content/unity-api.js in the unity-firefox-extension extension 2.4.1 for Firefox exposes the toDataURL function in an API call, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted webpage.
0
Attacker Value
Unknown

CVE-2012-4551

Disclosure Date: November 30, 2012 (last updated October 05, 2023)
Use-after-free vulnerability in libunity-webapps before 2.4.1 allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via a crafted web site, related to "certain hash tables."
0