Show filters
24 Total Results
Displaying 11-20 of 24
Sort by:
Attacker Value
Unknown

CVE-2019-8920

Disclosure Date: July 09, 2019 (last updated November 27, 2024)
iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569.
0
Attacker Value
Unknown

CVE-2019-12826

Disclosure Date: July 01, 2019 (last updated November 27, 2024)
A Cross-Site-Request-Forgery (CSRF) vulnerability in widget_logic.php in the 2by2host Widget Logic plugin before 5.10.2 for WordPress allows remote attackers to execute PHP code via snippets (that are attached to widgets and then eval'd to dynamically determine their visibility) by crafting a malicious POST request that tricks administrators into adding the code.
0
Attacker Value
Unknown

CVE-2019-8924

Disclosure Date: May 17, 2019 (last updated November 27, 2024)
XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued.
0
Attacker Value
Unknown

CVE-2019-8923

Disclosure Date: May 14, 2019 (last updated November 27, 2024)
XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. NOTE: This product is discontinued.
0
Attacker Value
Unknown

CVE-2015-8559

Disclosure Date: September 21, 2017 (last updated November 26, 2024)
The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/log/messages.
Attacker Value
Unknown

CVE-2017-7174

Disclosure Date: March 17, 2017 (last updated November 26, 2024)
The user-account creation feature in Chef Manage 2.1.0 through 2.4.4 allows remote attackers to execute arbitrary code. This is fixed in 2.4.5.
0
Attacker Value
Unknown

CVE-2016-4326

Disclosure Date: June 10, 2016 (last updated November 25, 2024)
The Chef Manage (formerly opscode-manage) add-on before 1.12.0 for Chef allows remote attackers to execute arbitrary code via crafted serialized data in a cookie.
0
Attacker Value
Unknown

CVE-2013-2586

Disclosure Date: September 29, 2014 (last updated October 05, 2023)
XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp and execute cross-site scripting (XSS) attacks via the WriteIntoLocalDisk method.
0
Attacker Value
Unknown

CVE-2014-5623

Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The penguinchefshop (aka com.freegames.penguinchefshop) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2008-6498

Disclosure Date: March 20, 2009 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in security/xamppsecurity.php in XAMPP 1.6.8 allows remote attackers to hijack the authentication of users for requests that change a certain .htaccess password via the xampppasswd parameter.
0