Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown
CVE-2024-8568
Disclosure Date: September 08, 2024 (last updated September 17, 2024)
A vulnerability, which was classified as critical, was found in Mini-Tmall up to 20240901. Affected is the function rewardMapper.select of the file tmall/admin/order/1/1. The manipulation of the argument orderBy leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2023-50630
Disclosure Date: January 04, 2024 (last updated January 11, 2024)
Cross Site Scripting (XSS) vulnerability in xiweicheng TMS v.2.28.0 allows a remote attacker to execute arbitrary code via a crafted script to the click here function.
0
Attacker Value
Unknown
CVE-2021-30134
Disclosure Date: December 26, 2022 (last updated February 24, 2025)
php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php.
0
Attacker Value
Unknown
CVE-2022-26247
Disclosure Date: March 20, 2022 (last updated February 23, 2025)
TMS v2.28.0 contains an insecure permissions vulnerability via the component /TMS/admin/user/Update2. This vulnerability allows attackers to modify the administrator account and password.
0
Attacker Value
Unknown
CVE-2015-5704
Disclosure Date: September 25, 2017 (last updated November 26, 2024)
scripts/licensecheck.pl in devscripts before 2.15.7 allows local users to execute arbitrary shell commands.
0
Attacker Value
Unknown
CVE-2015-5705
Disclosure Date: September 06, 2017 (last updated November 26, 2024)
Argument injection vulnerability in devscripts before 2.15.7 allows remote attackers to write to arbitrary files via a crafted symlink and crafted filename.
0
Attacker Value
Unknown
CVE-2015-5471
Disclosure Date: January 12, 2016 (last updated November 25, 2024)
Absolute path traversal vulnerability in include/user/download.php in the Swim Team plugin 1.44.10777 for WordPress allows remote attackers to read arbitrary files via a full pathname in the file parameter.
0
Attacker Value
Unknown
CVE-2013-0348
Disclosure Date: December 13, 2013 (last updated October 05, 2023)
thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allows local users to obtain sensitive information by reading the file.
0
Attacker Value
Unknown
CVE-2012-0958
Disclosure Date: December 26, 2012 (last updated October 05, 2023)
content/unity-api.js in the unity-firefox-extension extension 2.4.1 for Firefox exposes the toDataURL function in an API call, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted webpage.
0
Attacker Value
Unknown
CVE-2012-4551
Disclosure Date: November 30, 2012 (last updated October 05, 2023)
Use-after-free vulnerability in libunity-webapps before 2.4.1 allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via a crafted web site, related to "certain hash tables."
0