Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown

CVE-2020-12071

Disclosure Date: April 23, 2020 (last updated February 21, 2025)
Anchor 0.12.7 allows admins to cause XSS via crafted post content.
Attacker Value
Unknown

CVE-2018-1999033

Disclosure Date: August 01, 2018 (last updated November 27, 2024)
An exposure of sensitive information vulnerability exists in Jenkins Anchore Container Image Scanner Plugin 10.16 and earlier in AnchoreBuilder.java that allows attackers with Item/ExtendedRead permission or file system access to the Jenkins master to obtain the password stored in this plugin's configuration.
Attacker Value
Unknown

CVE-2018-7251

Disclosure Date: February 19, 2018 (last updated November 26, 2024)
An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contains MySQL credentials if a MySQL error (such as "Too many connections") has occurred.
0
Attacker Value
Unknown

CVE-2018-6460

Disclosure Date: January 31, 2018 (last updated November 26, 2024)
Hotspot Shield runs a webserver with a static IP address 127.0.0.1 and port 895. The web server uses JSONP and hosts sensitive information including configuration. User controlled input is not sufficiently filtered: an unauthenticated attacker can send a POST request to /status.js with the parameter func=$_APPLOG.Rfunc and extract sensitive information about the machine, including whether the user is connected to a VPN, to which VPN he/she is connected, and what is their real IP address.
0
Attacker Value
Unknown

CVE-2015-5060

Disclosure Date: September 07, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in anchor-cms before 0.9-dev.
0
Attacker Value
Unknown

CVE-2015-5687

Disclosure Date: October 05, 2015 (last updated October 05, 2023)
system/session/drivers/cookie.php in Anchor CMS 0.9.x allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in a cookie.
0
Attacker Value
Unknown

CVE-2014-9182

Disclosure Date: December 02, 2014 (last updated October 05, 2023)
models/comment.php in Anchor CMS 0.9.2 and earlier allows remote attackers to inject arbitrary headers into mail messages via a crafted Host: header.
0
Attacker Value
Unknown

CVE-2013-5099

Disclosure Date: August 09, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in article.php in Anchor CMS 0.9.1, when comments are enabled, allows remote attackers to inject arbitrary web script or HTML via the Name field. NOTE: some sources have reported that comments.php is vulnerable, but certain functions from comments.php are used by article.php.
0