Show filters
23 Total Results
Displaying 11-20 of 23
Sort by:
Attacker Value
Unknown
CVE-2019-7553
Disclosure Date: June 06, 2019 (last updated November 27, 2024)
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has Stored XSS in the Profile Update page via the My Name field.
0
Attacker Value
Unknown
CVE-2018-20637
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 allows remote attackers to cause a denial of service (unrecoverable blank profile) via crafted JavaScript code in the First Name and Last Name field.
0
Attacker Value
Unknown
CVE-2018-20638
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory.
0
Attacker Value
Unknown
CVE-2018-20636
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has HTML injection via the First Name field.
0
Attacker Value
Unknown
CVE-2018-15186
Disclosure Date: August 10, 2018 (last updated November 27, 2024)
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has CSRF via client/auditor/updprofile.php.
0
Attacker Value
Unknown
CVE-2018-13256
Disclosure Date: July 09, 2018 (last updated November 27, 2024)
PHP Scripts Mall Auditor Website 2.0.1 has XSS via the lastname or firstname parameter.
0
Attacker Value
Unknown
CVE-2018-10655
Disclosure Date: May 10, 2018 (last updated November 26, 2024)
DLPnpAuditor.exe in DeviceLock Plug and Play Auditor (freeware) 5.72 has a Unicode Buffer Overflow (SEH).
0
Attacker Value
Unknown
CVE-2017-17740
Disclosure Date: December 18, 2017 (last updated November 26, 2024)
contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation.
0
Attacker Value
Unknown
CVE-2017-17607
Disclosure Date: December 13, 2017 (last updated November 26, 2024)
CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail.
0
Attacker Value
Unknown
CVE-2017-9287
Disclosure Date: May 29, 2017 (last updated November 26, 2024)
servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with a page size of 0.
0