Show filters
39 Total Results
Displaying 11-20 of 39
Sort by:
Attacker Value
Unknown
CVE-2023-2863
Disclosure Date: May 24, 2023 (last updated February 25, 2025)
A vulnerability has been found in Simple Design Daily Journal 1.012.GP.B on Android and classified as problematic. Affected by this vulnerability is an unknown functionality of the component SQLite Database. The manipulation leads to cleartext storage in a file or on disk. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-229819.
0
Attacker Value
Unknown
CVE-2022-26616
Disclosure Date: April 04, 2022 (last updated February 23, 2025)
PKP Vendor Open Journal System v2.4.8 to v3.3.8 allows attackers to perform reflected cross-site scripting (XSS) attacks via crafted HTTP headers.
0
Attacker Value
Unknown
CVE-2022-24181
Disclosure Date: April 01, 2022 (last updated February 23, 2025)
Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.
0
Attacker Value
Unknown
CVE-2022-24582
Disclosure Date: February 24, 2022 (last updated February 23, 2025)
Accounting Journal Management 1.0 is vulnerable to XSS-PHPSESSID-Hijacking. The parameter manage_user from User lists is vulnerable to XSS-Stored and PHPSESSID attacks. The malicious user can attack the system by using the already session which he has from inside and outside of the network.
0
Attacker Value
Unknown
CVE-2020-15478
Disclosure Date: July 01, 2020 (last updated February 21, 2025)
The Journal theme before 3.1.0 for OpenCart allows exposure of sensitive data via SQL errors.
0
Attacker Value
Unknown
CVE-2019-19909
Disclosure Date: December 19, 2019 (last updated November 27, 2024)
An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injection can occur in the OJS report generator if an authenticated Journal Manager user visits a crafted URL, because unserialize is used.
0
Attacker Value
Unknown
CVE-2018-12229
Disclosure Date: June 12, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Public Knowledge Project (PKP) Open Journal System (OJS) 3.0.0 to 3.1.1-1 allows remote attackers to inject arbitrary web script or HTML via the templates/frontend/pages/search.tpl parameter (aka the By Author field).
0
Attacker Value
Unknown
CVE-2017-6022
Disclosure Date: June 30, 2017 (last updated November 26, 2024)
A hard-coded password issue was discovered in Becton, Dickinson and Company (BD) PerformA, Version 2.0.14.0 and prior versions, and KLA Journal Service, Version 1.0.51 and prior versions. They use hard-coded passwords to access the BD Kiestra Database, which could be leveraged to compromise the confidentiality of limited PHI/PII information stored in the BD Kiestra Database.
0
Attacker Value
Unknown
CVE-2014-7116
Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The NRA Journal (aka com.magazinecloner.nationalrifleassociationjournal) application @7F080181 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-7122
Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The Lansing State Journal Print (aka com.lansingjournal.android.prod) application 6.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0