Show filters
29 Total Results
Displaying 11-20 of 29
Sort by:
Attacker Value
Unknown

CVE-2014-4561

Disclosure Date: January 10, 2020 (last updated February 21, 2025)
The ultimate-weather plugin 1.0 for WordPress has XSS
Attacker Value
Unknown

CVE-2018-18875

Disclosure Date: June 18, 2019 (last updated November 27, 2024)
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a stored Cross-site scripting (XSS) vulnerability allows remote authenticated users to inject arbitrary web script via changestationname.php.
0
Attacker Value
Unknown

CVE-2018-18878

Disclosure Date: June 18, 2019 (last updated November 27, 2024)
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, the BACnet daemon does not properly validate input, which could allow a remote attacker to send specially crafted packets causing the device to become unavailable.
0
Attacker Value
Unknown

CVE-2018-18876

Disclosure Date: June 18, 2019 (last updated November 27, 2024)
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a readouts_rd.php directory traversal issue makes it possible to read any file present on the underlying operating system.
0
Attacker Value
Unknown

CVE-2018-18877

Disclosure Date: June 18, 2019 (last updated November 27, 2024)
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can access an alternative configuration page config_main.php that allows manipulation of the device.
0
Attacker Value
Unknown

CVE-2018-18879

Disclosure Date: June 18, 2019 (last updated November 27, 2024)
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to the underlying operating system as user input is not sanitized in networkdiags.php.
0
Attacker Value
Unknown

CVE-2018-18880

Disclosure Date: June 18, 2019 (last updated November 27, 2024)
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a networkdiags.php reflected Cross-site scripting (XSS) vulnerability allows remote authenticated users to inject arbitrary web script.
0
Attacker Value
Unknown

CVE-2017-16184

Disclosure Date: June 07, 2018 (last updated November 26, 2024)
scott-blanch-weather-app is a sample Node.js app using Express 4. scott-blanch-weather-app is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
0
Attacker Value
Unknown

CVE-2017-16110

Disclosure Date: June 07, 2018 (last updated November 26, 2024)
weather.swlyons is a simple web server for weather updates. weather.swlyons is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
0
Attacker Value
Unknown

CVE-2014-6699

Disclosure Date: September 24, 2014 (last updated October 05, 2023)
The Weather Channel (aka com.weather.Weather) application 5.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0