Show filters
24 Total Results
Displaying 11-20 of 24
Sort by:
Attacker Value
Unknown

CVE-2022-23072

Disclosure Date: June 21, 2022 (last updated February 23, 2025)
In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in “Add to Cart” functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascript payload in the ‘Name’ parameter and clicks on the Add to Shopping Cart icon, an XSS payload will trigger. A low privileged attacker will have the victim's API key and can lead to admin's account takeover.
0
Attacker Value
Unknown

CVE-2022-23071

Disclosure Date: June 19, 2022 (last updated February 23, 2025)
In Recipes, versions 0.9.1 through 1.2.5 are vulnerable to Server Side Request Forgery (SSRF), in the “Import Recipe” functionality. When an attacker enters the localhost URL, a low privileged attacker can access/read the internal file system to access sensitive information.
Attacker Value
Unknown

CVE-2017-8940

Disclosure Date: May 15, 2017 (last updated November 08, 2023)
The Zipongo - Healthy Recipes and Grocery Deals app before 6.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2016-1000147

Disclosure Date: October 10, 2016 (last updated November 25, 2024)
Reflected XSS in wordpress plugin recipes-writer v1.0.4
0
Attacker Value
Unknown

CVE-2014-9440

Disclosure Date: January 02, 2015 (last updated October 05, 2023)
SQL injection vulnerability in browse.php in phpMyRecipes 1.2.2 allows remote attackers to execute arbitrary SQL commands via the category parameter.
0
Attacker Value
Unknown

CVE-2014-9347

Disclosure Date: December 08, 2014 (last updated October 05, 2023)
SQL injection vulnerability in dosearch.php in phpMyRecipes 1.2.2 allows remote attackers to execute arbitrary SQL commands via the words_exact parameter.
0
Attacker Value
Unknown

CVE-2014-7454

Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The Detox Juicing Diet Recipes (aka com.wDetoxJuicingDietRecipes) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-7476

Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The Healthy Lunch Diet Recipes (aka com.best.lunchdietrecipes) application 3.6.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2010-5039

Disclosure Date: November 02, 2011 (last updated October 04, 2023)
SQL injection vulnerability in control/admin_login.php in ScriptsFeed Recipes Listing Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter (aka the UserName field). NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-6943

Disclosure Date: August 12, 2009 (last updated October 04, 2023)
Unrestricted file upload vulnerability in ScriptsFeed Recipes Listing Portal allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a recipe photo, then accessing it via a direct request to the file in pictures/.
0