Show filters
67 Total Results
Displaying 11-20 of 67
Sort by:
Attacker Value
Unknown

CVE-2023-4491

Disclosure Date: October 04, 2023 (last updated October 09, 2023)
Buffer overflow vulnerability in Easy Address Book Web Server 1.6 version. The exploitation of this vulnerability could allow an attacker to send a very long username string to /searchbook.ghp, asking for the name via a POST request, resulting in arbitrary code execution on the remote machine.
Attacker Value
Unknown

CVE-2023-38390

Disclosure Date: October 03, 2023 (last updated October 09, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Anshul Labs Mobile Address Bar Changer plugin <= 3.0 versions.
Attacker Value
Unknown

CVE-2023-34184

Disclosure Date: August 30, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Bhavik Patel Woocommerce Order address Print plugin <= 3.2 versions.
Attacker Value
Unknown

CVE-2014-125058

Disclosure Date: January 07, 2023 (last updated October 20, 2023)
A vulnerability was found in LearnMeSomeCodes project3 and classified as critical. This issue affects the function search_first_name of the file search.rb. The manipulation leads to sql injection. The patch is named d3efa17ae9f6b2fc25a6bbcf165cefed17c7035e. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217607. NOTE: Maintainer is aware of this issue as remarked in the source code.
Attacker Value
Unknown

CVE-2020-29474

Disclosure Date: December 24, 2020 (last updated February 22, 2025)
EGavilan Media EGM Address Book 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution.
Attacker Value
Unknown

CVE-2020-35276

Disclosure Date: December 21, 2020 (last updated February 22, 2025)
EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.
Attacker Value
Unknown

CVE-2019-15833

Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The simple-mail-address-encoder plugin before 1.7 for WordPress has reflected XSS.
Attacker Value
Unknown

CVE-2019-15770

Disclosure Date: August 29, 2019 (last updated November 27, 2024)
The woo-address-book plugin before 1.6.0 for WordPress has save calls without nonce verification checks.
0
Attacker Value
Unknown

CVE-2018-13797

Disclosure Date: July 10, 2018 (last updated November 27, 2024)
The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.
0
Attacker Value
Unknown

CVE-2018-12558

Disclosure Date: June 20, 2018 (last updated November 26, 2024)
The parse() method in the Email::Address module through 1.909 for Perl is vulnerable to Algorithmic complexity on specially prepared input, leading to Denial of Service. Prepared special input that caused this problem contained 30 form-field characters ("\f").
0