Show filters
67 Total Results
Displaying 11-20 of 67
Sort by:
Attacker Value
Unknown
CVE-2023-4491
Disclosure Date: October 04, 2023 (last updated October 09, 2023)
Buffer overflow vulnerability in Easy Address Book Web Server 1.6 version. The exploitation of this vulnerability could allow an attacker to send a very long username string to /searchbook.ghp, asking for the name via a POST request, resulting in arbitrary code execution on the remote machine.
0
Attacker Value
Unknown
CVE-2023-38390
Disclosure Date: October 03, 2023 (last updated October 09, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Anshul Labs Mobile Address Bar Changer plugin <= 3.0 versions.
0
Attacker Value
Unknown
CVE-2023-34184
Disclosure Date: August 30, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Bhavik Patel Woocommerce Order address Print plugin <= 3.2 versions.
0
Attacker Value
Unknown
CVE-2014-125058
Disclosure Date: January 07, 2023 (last updated October 20, 2023)
A vulnerability was found in LearnMeSomeCodes project3 and classified as critical. This issue affects the function search_first_name of the file search.rb. The manipulation leads to sql injection. The patch is named d3efa17ae9f6b2fc25a6bbcf165cefed17c7035e. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217607. NOTE: Maintainer is aware of this issue as remarked in the source code.
0
Attacker Value
Unknown
CVE-2020-29474
Disclosure Date: December 24, 2020 (last updated February 22, 2025)
EGavilan Media EGM Address Book 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution.
0
Attacker Value
Unknown
CVE-2020-35276
Disclosure Date: December 21, 2020 (last updated February 22, 2025)
EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.
0
Attacker Value
Unknown
CVE-2019-15833
Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The simple-mail-address-encoder plugin before 1.7 for WordPress has reflected XSS.
0
Attacker Value
Unknown
CVE-2019-15770
Disclosure Date: August 29, 2019 (last updated November 27, 2024)
The woo-address-book plugin before 1.6.0 for WordPress has save calls without nonce verification checks.
0
Attacker Value
Unknown
CVE-2018-13797
Disclosure Date: July 10, 2018 (last updated November 27, 2024)
The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.
0
Attacker Value
Unknown
CVE-2018-12558
Disclosure Date: June 20, 2018 (last updated November 26, 2024)
The parse() method in the Email::Address module through 1.909 for Perl is vulnerable to Algorithmic complexity on specially prepared input, leading to Denial of Service. Prepared special input that caused this problem contained 30 form-field characters ("\f").
0