Show filters
36 Total Results
Displaying 11-20 of 36
Sort by:
Attacker Value
Unknown
CVE-2021-40909
Disclosure Date: January 24, 2022 (last updated February 23, 2025)
Cross site scripting (XSS) vulnerability in sourcecodester PHP CRUD without Refresh/Reload using Ajax and DataTables Tutorial v1 by oretnom23, allows remote attackers to execute arbitrary code via the first_name, last_name, and email parameters to /ajax_crud.
0
Attacker Value
Unknown
CVE-2021-43853
Disclosure Date: December 22, 2021 (last updated February 23, 2025)
Ajax.NET Professional (AjaxPro) is an AJAX framework available for Microsoft ASP.NET. Affected versions of this package are vulnerable to JavaScript object injection which may result in cross site scripting when leveraged by a malicious user. The affected core relates to JavaScript object creation when parsing json input. Releases before version 21.12.22.1 are affected. A workaround exists that replaces one of the core JavaScript files embedded in the library. See the GHSA-5q7q-qqw2-hjq7 for workaround details.
0
Attacker Value
Unknown
CVE-2016-10929
Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The advanced-ajax-page-loader plugin before 2.7.7 for WordPress has no protection against the reading of uploaded files when not logged in.
0
Attacker Value
Unknown
CVE-2018-15876
Disclosure Date: August 26, 2018 (last updated November 27, 2024)
An issue was discovered in the ajax-bootmodal-login plugin 1.4.3 for WordPress. The register form, login form, and password-recovery form require solving a CAPTCHA to perform actions. However, this is required only once per user session, and therefore one could send as many requests as one wished by automation.
0
Attacker Value
Unknown
CVE-2014-2674
Disclosure Date: March 19, 2018 (last updated November 26, 2024)
Directory traversal vulnerability in the Ajax Pagination (twitter Style) plugin 1.1 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the loop parameter in an ajax_navigation action to wp-admin/admin-ajax.php.
0
Attacker Value
Unknown
CVE-2014-4972
Disclosure Date: January 08, 2018 (last updated November 26, 2024)
Unrestricted file upload vulnerability in the Gravity Upload Ajax plugin 1.1 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file under wp-content/uploads/gravity_forms.
0
Attacker Value
Unknown
CVE-2016-1000127
Disclosure Date: October 10, 2016 (last updated November 25, 2024)
Reflected XSS in wordpress plugin ajax-random-post v2.00
0
Attacker Value
Unknown
CVE-2015-5650
Disclosure Date: October 06, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in AjaXplorer 2.0 allows remote attackers to read arbitrary files via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-3392
Disclosure Date: April 21, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Ajax Timeline module before 7.x-1.1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a node title.
0
Attacker Value
Unknown
CVE-2012-5853
Disclosure Date: January 08, 2015 (last updated October 05, 2023)
SQL injection vulnerability in the "the_search_function" function in cardoza_ajax_search.php in the AJAX Post Search (cardoza-ajax-search) plugin before 1.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the srch_txt parameter in a "the_search_text" action to wp-admin/admin-ajax.php.
0