Show filters
22 Total Results
Displaying 11-20 of 22
Sort by:
Attacker Value
Unknown

CVE-2023-50249

Disclosure Date: December 20, 2023 (last updated December 29, 2023)
Sentry-Javascript is official Sentry SDKs for JavaScript. A ReDoS (Regular expression Denial of Service) vulnerability has been identified in Sentry's Astro SDK 7.78.0-7.86.0. Under certain conditions, this vulnerability allows an attacker to cause excessive computation times on the server, leading to denial of service (DoS). This vulnerability has been patched in sentry/astro version 7.87.0.
Attacker Value
Unknown

CVE-2021-40511

Disclosure Date: June 21, 2022 (last updated October 07, 2023)
OBDA systems’ Mastro 1.0 is vulnerable to XML Entity Expansion (aka “billion laughs”) attack allowing denial of service.
Attacker Value
Unknown

CVE-2021-40510

Disclosure Date: June 21, 2022 (last updated October 07, 2023)
XML eXternal Entity (XXE) in OBDA systems’ Mastro 1.0 allows remote attackers to read system files via custom DTDs.
Attacker Value
Unknown

CVE-2018-7180

Disclosure Date: February 17, 2018 (last updated November 26, 2024)
SQL Injection exists in the Saxum Astro 4.0.14 component for Joomla! via the publicid parameter.
0
Attacker Value
Unknown

CVE-2014-5659

Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The ASTRO File Manager with Cloud (aka com.metago.astro) application ASTRO-4.4.592 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2009-4685

Disclosure Date: March 10, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in celebrities.php in PHP Scripts Now Astrology allows remote attackers to inject arbitrary web script or HTML via the day parameter.
0
Attacker Value
Unknown

CVE-2009-4675

Disclosure Date: March 05, 2010 (last updated October 04, 2023)
admin/admin_info/index.php in the Mole Group Gastro Portal (Restaurant Directory) Script does not require administrative authentication, which allows remote attackers to change the admin password via an unspecified form submission.
0
Attacker Value
Unknown

CVE-2008-4642

Disclosure Date: October 21, 2008 (last updated October 04, 2023)
SQL injection vulnerability in profile.php in AstroSPACES 1.1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action.
0
Attacker Value
Unknown

CVE-2008-2075

Disclosure Date: May 05, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in pic.php in AstroCam 2.5.0 through 2.7.3 allows remote attackers to inject arbitrary web script or HTML via the picfile parameter.
0
Attacker Value
Unknown

CVE-2008-0605

Disclosure Date: February 06, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in AstroSoft HelpDesk before 1.95.228 allow remote attackers to inject arbitrary web script or HTML via the (1) txtSearch parameter to operator/article/article_search_results.asp and the (2) Attach_Id parameter to operator/article/article_attachment.asp. NOTE: for vector 2, the XSS occurs in a forced SQL error message.
0