Show filters
16 Total Results
Displaying 11-16 of 16
Sort by:
Attacker Value
Unknown

CVE-2017-6072

Disclosure Date: February 21, 2017 (last updated November 26, 2024)
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via defaultadmin.
0
Attacker Value
Unknown

CVE-2017-6071

Disclosure Date: February 21, 2017 (last updated November 26, 2024)
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via exportxml.
Attacker Value
Unknown

CVE-2014-8539

Disclosure Date: November 21, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Simple Email Form 1.8.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the mod_simpleemailform_field2_1 parameter to index.php.
0
Attacker Value
Unknown

CVE-2014-8955

Disclosure Date: November 17, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Contact Form Clean and Simple (clean-and-simple-contact-form-by-meg-nicholas) plugin 4.4.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the cscf[name] parameter to contact-us/.
0
Attacker Value
Unknown

CVE-2013-5963

Disclosure Date: September 30, 2013 (last updated October 05, 2023)
Unrestricted file upload vulnerability in multi.php in Simple Dropbox Upload plugin before 1.8.8.1 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/wpdb/.
0
Attacker Value
Unknown

CVE-2010-5038

Disclosure Date: November 02, 2011 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in contact/contact.php in Groone's Simple Contact Form allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.
0