Show filters
24 Total Results
Displaying 11-20 of 24
Sort by:
Attacker Value
Unknown
CVE-2019-8920
Disclosure Date: July 09, 2019 (last updated November 27, 2024)
iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569.
0
Attacker Value
Unknown
CVE-2019-12826
Disclosure Date: July 01, 2019 (last updated November 27, 2024)
A Cross-Site-Request-Forgery (CSRF) vulnerability in widget_logic.php in the 2by2host Widget Logic plugin before 5.10.2 for WordPress allows remote attackers to execute PHP code via snippets (that are attached to widgets and then eval'd to dynamically determine their visibility) by crafting a malicious POST request that tricks administrators into adding the code.
0
Attacker Value
Unknown
CVE-2019-8924
Disclosure Date: May 17, 2019 (last updated November 27, 2024)
XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued.
0
Attacker Value
Unknown
CVE-2019-8923
Disclosure Date: May 14, 2019 (last updated November 27, 2024)
XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. NOTE: This product is discontinued.
0
Attacker Value
Unknown
CVE-2015-8559
Disclosure Date: September 21, 2017 (last updated November 26, 2024)
The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/log/messages.
0
Attacker Value
Unknown
CVE-2017-7174
Disclosure Date: March 17, 2017 (last updated November 26, 2024)
The user-account creation feature in Chef Manage 2.1.0 through 2.4.4 allows remote attackers to execute arbitrary code. This is fixed in 2.4.5.
0
Attacker Value
Unknown
CVE-2016-4326
Disclosure Date: June 10, 2016 (last updated November 25, 2024)
The Chef Manage (formerly opscode-manage) add-on before 1.12.0 for Chef allows remote attackers to execute arbitrary code via crafted serialized data in a cookie.
0
Attacker Value
Unknown
CVE-2013-2586
Disclosure Date: September 29, 2014 (last updated October 05, 2023)
XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp and execute cross-site scripting (XSS) attacks via the WriteIntoLocalDisk method.
0
Attacker Value
Unknown
CVE-2014-5623
Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The penguinchefshop (aka com.freegames.penguinchefshop) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2008-6498
Disclosure Date: March 20, 2009 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in security/xamppsecurity.php in XAMPP 1.6.8 allows remote attackers to hijack the authentication of users for requests that change a certain .htaccess password via the xampppasswd parameter.
0