Show filters
25 Total Results
Displaying 11-20 of 25
Sort by:
Attacker Value
Unknown
CVE-2010-4659
Disclosure Date: November 20, 2019 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in statusnet through 2010 in error message contents.
0
Attacker Value
Unknown
CVE-2010-4660
Disclosure Date: November 20, 2019 (last updated November 27, 2024)
Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes..
0
Attacker Value
Unknown
CVE-2011-3370
Disclosure Date: November 12, 2019 (last updated November 27, 2024)
statusnet before 0.9.9 has XSS
0
Attacker Value
Unknown
CVE-2019-16524
Disclosure Date: September 26, 2019 (last updated November 27, 2024)
The easy-fancybox plugin before 1.8.18 for WordPress (aka Easy FancyBox) is susceptible to Stored XSS in the Settings Menu inc/class-easyfancybox.php due to improper encoding of arbitrarily submitted settings parameters. This occurs because there is no inline styles output filter.
0
Attacker Value
Unknown
CVE-2019-15479
Disclosure Date: August 26, 2019 (last updated November 27, 2024)
Status Board 1.1.81 has reflected XSS via dashboard.ts.
0
Attacker Value
Unknown
CVE-2019-15478
Disclosure Date: August 26, 2019 (last updated November 27, 2024)
Status Board 1.1.81 has reflected XSS via logic.ts.
0
Attacker Value
Unknown
CVE-2019-12164
Disclosure Date: July 23, 2019 (last updated November 27, 2024)
ubuntu-server.js in Status React Native Desktop before v0.57.8_mobile_ui allows Remote Code Execution.
0
Attacker Value
Unknown
CVE-2014-5094
Disclosure Date: October 20, 2014 (last updated October 05, 2023)
Status2k allows remote attackers to obtain configuration information via a phpinfo action in a request to status/index.php, which calls the phpinfo function.
0
Attacker Value
Unknown
CVE-2014-5923
Disclosure Date: September 18, 2014 (last updated October 05, 2023)
The Facebook Status Via (aka com.StatusViaAdvanced) application 3.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-5089
Disclosure Date: August 06, 2014 (last updated October 05, 2023)
SQL injection vulnerability in admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary SQL commands via the log parameter.
0