Show filters
16 Total Results
Displaying 11-16 of 16
Sort by:
Attacker Value
Unknown
CVE-2017-6072
Disclosure Date: February 21, 2017 (last updated November 26, 2024)
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via defaultadmin.
0
Attacker Value
Unknown
CVE-2017-6071
Disclosure Date: February 21, 2017 (last updated November 26, 2024)
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via exportxml.
0
Attacker Value
Unknown
CVE-2014-8539
Disclosure Date: November 21, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Simple Email Form 1.8.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the mod_simpleemailform_field2_1 parameter to index.php.
0
Attacker Value
Unknown
CVE-2014-8955
Disclosure Date: November 17, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Contact Form Clean and Simple (clean-and-simple-contact-form-by-meg-nicholas) plugin 4.4.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the cscf[name] parameter to contact-us/.
0
Attacker Value
Unknown
CVE-2013-5963
Disclosure Date: September 30, 2013 (last updated October 05, 2023)
Unrestricted file upload vulnerability in multi.php in Simple Dropbox Upload plugin before 1.8.8.1 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/wpdb/.
0
Attacker Value
Unknown
CVE-2010-5038
Disclosure Date: November 02, 2011 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in contact/contact.php in Groone's Simple Contact Form allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.
0