Show filters
571 Total Results
Displaying 11-20 of 571
Sort by:
Attacker Value
Unknown

CVE-2024-9101

Disclosure Date: December 19, 2024 (last updated December 20, 2024)
A reflected cross-site scripting (XSS) vulnerability in the 'Entry Chooser' of phpLDAPadmin (version 1.2.1 through the latest version, 1.2.6.7) allows attackers to execute arbitrary JavaScript in the user's browser via the 'element' parameter, which is unsafely passed to the JavaScript 'eval' function. However, exploitation is limited to specific conditions where 'opener' is correctly set.
0
Attacker Value
Unknown

CVE-2024-30376

Disclosure Date: November 22, 2024 (last updated January 13, 2025)
Famatech Advanced IP Scanner Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Famatech Advanced IP Scanner. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the application's use of Qt. The application loads Qt plugins from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of an administrator. Was ZDI-CAN-20768.
Attacker Value
Unknown

CVE-2024-10749

Disclosure Date: November 04, 2024 (last updated November 07, 2024)
A vulnerability, which was classified as critical, was found in ThinkAdmin up to 6.1.67. Affected is the function script of the file /app/admin/controller/api/Plugs.php. The manipulation of the argument uptoken leads to deserialization. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2024-48230

Disclosure Date: October 25, 2024 (last updated November 01, 2024)
funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php.
Attacker Value
Unknown

CVE-2024-48229

Disclosure Date: October 25, 2024 (last updated November 01, 2024)
funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin.
Attacker Value
Unknown

CVE-2024-48227

Disclosure Date: October 25, 2024 (last updated November 01, 2024)
Funadmin 5.0.2 has a logical flaw in the Curd one click command deletion function, which can result in a Denial of Service (DOS).
Attacker Value
Unknown

CVE-2024-48226

Disclosure Date: October 25, 2024 (last updated November 01, 2024)
Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield.
Attacker Value
Unknown

CVE-2024-48225

Disclosure Date: October 25, 2024 (last updated November 01, 2024)
Funadmin v5.0.2 has an arbitrary file deletion vulnerability in /curd/index/delfile.
Attacker Value
Unknown

CVE-2024-48224

Disclosure Date: October 25, 2024 (last updated November 01, 2024)
Funadmin v5.0.2 has an arbitrary file read vulnerability in /curd/index/editfile.
Attacker Value
Unknown

CVE-2024-48223

Disclosure Date: October 25, 2024 (last updated November 01, 2024)
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist.