Show filters
84 Total Results
Displaying 11-20 of 84
Sort by:
Attacker Value
Unknown
CVE-2023-25350
Disclosure Date: March 24, 2023 (last updated February 23, 2025)
Faveo Helpdesk 1.0-1.11.1 is vulnerable to SQL Injection. When the user logs in through the login box, he has no judgment on the validity of the user's input data. The parameters passed from the front end to the back end are controllable, which will lead to SQL injection.
0
Attacker Value
Unknown
CVE-2023-24625
Disclosure Date: March 24, 2023 (last updated February 23, 2025)
Faveo 5.0.1 allows remote attackers to obtain sensitive information via a modified user ID in an Insecure Direct Object Reference (IDOR) attack.
0
Attacker Value
Unknown
CVE-2021-4274
Disclosure Date: December 21, 2022 (last updated February 24, 2025)
A vulnerability, which was classified as problematic, has been found in sileht bird-lg. This issue affects some unknown processing of the file templates/layout.html. The manipulation of the argument request_args leads to cross site scripting. The attack may be initiated remotely. The name of the patch is ef6b32c527478fefe7a4436e10b96ee28ed5b308. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216479.
0
Attacker Value
Unknown
CVE-2022-27438
Disclosure Date: June 06, 2022 (last updated February 23, 2025)
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check.
0
Attacker Value
Unknown
CVE-2021-33570
Disclosure Date: May 25, 2021 (last updated February 22, 2025)
Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can result in reading local files via vectors involving XMLHttpRequest and open of a file:/// URL, or discovering PostgreSQL passwords via vectors involving Window.localStorage and savedConnections.
0
Attacker Value
Unknown
CVE-2019-15054
Disclosure Date: November 18, 2019 (last updated November 27, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in Mailbird before 2.7.5.0 r allow remote attackers to execute arbitrary JavaScript in a privileged context via a crafted HTML mail message. This vulnerability is distinct from CVE-2015-4657.
0
Attacker Value
Unknown
CVE-2018-20437
Disclosure Date: December 25, 2018 (last updated November 08, 2023)
An issue was discovered in the fileDownload function in the CommonController class in FEBS-Shiro before 2018-11-05. An attacker can download a file via a request of the form /common/download?filename=1.jsp&delete=false. NOTE: the software maintainer disputes the significance of this report because the product uses a JAR archive for deployment, and this contains application.yml with configuration data
0
Attacker Value
Unknown
CVE-2018-12066
Disclosure Date: June 08, 2018 (last updated November 26, 2024)
BIRD Internet Routing Daemon before 1.6.4 allows local users to cause a denial of service (stack consumption and daemon crash) via BGP mask expressions in birdc.
0
Attacker Value
Unknown
CVE-2017-16154
Disclosure Date: June 07, 2018 (last updated November 26, 2024)
earlybird is a web server module for early development. earlybird is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
0
Attacker Value
Unknown
CVE-2017-11509
Disclosure Date: March 28, 2018 (last updated November 26, 2024)
An authenticated remote attacker can execute arbitrary code in Firebird SQL Server versions 2.5.7 and 3.0.2 by executing a malformed SQL statement.
0