Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown
CVE-2020-12071
Disclosure Date: April 23, 2020 (last updated February 21, 2025)
Anchor 0.12.7 allows admins to cause XSS via crafted post content.
0
Attacker Value
Unknown
CVE-2018-1999033
Disclosure Date: August 01, 2018 (last updated November 27, 2024)
An exposure of sensitive information vulnerability exists in Jenkins Anchore Container Image Scanner Plugin 10.16 and earlier in AnchoreBuilder.java that allows attackers with Item/ExtendedRead permission or file system access to the Jenkins master to obtain the password stored in this plugin's configuration.
0
Attacker Value
Unknown
CVE-2018-7251
Disclosure Date: February 19, 2018 (last updated November 26, 2024)
An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contains MySQL credentials if a MySQL error (such as "Too many connections") has occurred.
0
Attacker Value
Unknown
CVE-2018-6460
Disclosure Date: January 31, 2018 (last updated November 26, 2024)
Hotspot Shield runs a webserver with a static IP address 127.0.0.1 and port 895. The web server uses JSONP and hosts sensitive information including configuration. User controlled input is not sufficiently filtered: an unauthenticated attacker can send a POST request to /status.js with the parameter func=$_APPLOG.Rfunc and extract sensitive information about the machine, including whether the user is connected to a VPN, to which VPN he/she is connected, and what is their real IP address.
0
Attacker Value
Unknown
CVE-2015-5060
Disclosure Date: September 07, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in anchor-cms before 0.9-dev.
0
Attacker Value
Unknown
CVE-2015-5687
Disclosure Date: October 05, 2015 (last updated October 05, 2023)
system/session/drivers/cookie.php in Anchor CMS 0.9.x allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in a cookie.
0
Attacker Value
Unknown
CVE-2014-9182
Disclosure Date: December 02, 2014 (last updated October 05, 2023)
models/comment.php in Anchor CMS 0.9.2 and earlier allows remote attackers to inject arbitrary headers into mail messages via a crafted Host: header.
0
Attacker Value
Unknown
CVE-2013-5099
Disclosure Date: August 09, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in article.php in Anchor CMS 0.9.1, when comments are enabled, allows remote attackers to inject arbitrary web script or HTML via the Name field. NOTE: some sources have reported that comments.php is vulnerable, but certain functions from comments.php are used by article.php.
0