Show filters
571 Total Results
Displaying 11-20 of 571
Sort by:
Attacker Value
Unknown
CVE-2024-9101
Disclosure Date: December 19, 2024 (last updated December 20, 2024)
A reflected cross-site scripting (XSS) vulnerability in the 'Entry Chooser' of phpLDAPadmin (version 1.2.1 through the latest version, 1.2.6.7) allows attackers to execute arbitrary JavaScript in the user's browser via the 'element' parameter, which is unsafely passed to the JavaScript 'eval' function. However, exploitation is limited to specific conditions where 'opener' is correctly set.
0
Attacker Value
Unknown
CVE-2024-30376
Disclosure Date: November 22, 2024 (last updated January 13, 2025)
Famatech Advanced IP Scanner Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Famatech Advanced IP Scanner. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the application's use of Qt. The application loads Qt plugins from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of an administrator. Was ZDI-CAN-20768.
0
Attacker Value
Unknown
CVE-2024-10749
Disclosure Date: November 04, 2024 (last updated November 07, 2024)
A vulnerability, which was classified as critical, was found in ThinkAdmin up to 6.1.67. Affected is the function script of the file /app/admin/controller/api/Plugs.php. The manipulation of the argument uptoken leads to deserialization. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-48230
Disclosure Date: October 25, 2024 (last updated November 01, 2024)
funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php.
0
Attacker Value
Unknown
CVE-2024-48229
Disclosure Date: October 25, 2024 (last updated November 01, 2024)
funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin.
0
Attacker Value
Unknown
CVE-2024-48227
Disclosure Date: October 25, 2024 (last updated November 01, 2024)
Funadmin 5.0.2 has a logical flaw in the Curd one click command deletion function, which can result in a Denial of Service (DOS).
0
Attacker Value
Unknown
CVE-2024-48226
Disclosure Date: October 25, 2024 (last updated November 01, 2024)
Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield.
0
Attacker Value
Unknown
CVE-2024-48225
Disclosure Date: October 25, 2024 (last updated November 01, 2024)
Funadmin v5.0.2 has an arbitrary file deletion vulnerability in /curd/index/delfile.
0
Attacker Value
Unknown
CVE-2024-48224
Disclosure Date: October 25, 2024 (last updated November 01, 2024)
Funadmin v5.0.2 has an arbitrary file read vulnerability in /curd/index/editfile.
0
Attacker Value
Unknown
CVE-2024-48223
Disclosure Date: October 25, 2024 (last updated November 01, 2024)
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist.
0