Show filters
25 Total Results
Displaying 11-20 of 25
Sort by:
Attacker Value
Unknown

CVE-2010-4659

Disclosure Date: November 20, 2019 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in statusnet through 2010 in error message contents.
Attacker Value
Unknown

CVE-2010-4660

Disclosure Date: November 20, 2019 (last updated November 27, 2024)
Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes..
Attacker Value
Unknown

CVE-2011-3370

Disclosure Date: November 12, 2019 (last updated November 27, 2024)
statusnet before 0.9.9 has XSS
Attacker Value
Unknown

CVE-2019-16524

Disclosure Date: September 26, 2019 (last updated November 27, 2024)
The easy-fancybox plugin before 1.8.18 for WordPress (aka Easy FancyBox) is susceptible to Stored XSS in the Settings Menu inc/class-easyfancybox.php due to improper encoding of arbitrarily submitted settings parameters. This occurs because there is no inline styles output filter.
Attacker Value
Unknown

CVE-2019-15479

Disclosure Date: August 26, 2019 (last updated November 27, 2024)
Status Board 1.1.81 has reflected XSS via dashboard.ts.
0
Attacker Value
Unknown

CVE-2019-15478

Disclosure Date: August 26, 2019 (last updated November 27, 2024)
Status Board 1.1.81 has reflected XSS via logic.ts.
0
Attacker Value
Unknown

CVE-2019-12164

Disclosure Date: July 23, 2019 (last updated November 27, 2024)
ubuntu-server.js in Status React Native Desktop before v0.57.8_mobile_ui allows Remote Code Execution.
0
Attacker Value
Unknown

CVE-2014-5094

Disclosure Date: October 20, 2014 (last updated October 05, 2023)
Status2k allows remote attackers to obtain configuration information via a phpinfo action in a request to status/index.php, which calls the phpinfo function.
0
Attacker Value
Unknown

CVE-2014-5923

Disclosure Date: September 18, 2014 (last updated October 05, 2023)
The Facebook Status Via (aka com.StatusViaAdvanced) application 3.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-5089

Disclosure Date: August 06, 2014 (last updated October 05, 2023)
SQL injection vulnerability in admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary SQL commands via the log parameter.
0