Show filters
57 Total Results
Displaying 11-20 of 57
Sort by:
Attacker Value
Unknown
CVE-2021-36750
Disclosure Date: December 22, 2021 (last updated October 07, 2023)
ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names).
0
Attacker Value
Unknown
CVE-2021-27888
Disclosure Date: March 02, 2021 (last updated February 22, 2025)
ZendTo before 6.06-4 Beta allows XSS during the display of a drop-off in which a filename has unexpected characters.
0
Attacker Value
Unknown
CVE-2020-8984
Disclosure Date: March 24, 2020 (last updated February 21, 2025)
lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header.
0
Attacker Value
Unknown
CVE-2020-8986
Disclosure Date: March 24, 2020 (last updated February 21, 2025)
lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta failed to properly check for equality when validating the session cookie, allowing an attacker to gain administrative access with a large number of requests.
0
Attacker Value
Unknown
CVE-2020-8985
Disclosure Date: March 24, 2020 (last updated February 21, 2025)
ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality.
0
Attacker Value
Unknown
CVE-2014-8089
Disclosure Date: February 17, 2020 (last updated February 21, 2025)
SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands via a null byte.
0
Attacker Value
Unknown
CVE-2015-3154
Disclosure Date: January 27, 2020 (last updated February 21, 2025)
CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email.
0
Attacker Value
Unknown
CVE-2012-4451
Disclosure Date: January 03, 2020 (last updated February 21, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) Debug, (2) Feed\PubSubHubbub, (3) Log\Formatter\Xml, (4) Tag\Cloud\Decorator, (5) Uri, (6) View\Helper\HeadStyle, (7) View\Helper\Navigation\Sitemap, or (8) View\Helper\Placeholder\Container\AbstractStandalone, related to Escaper.
0
Attacker Value
Unknown
CVE-2014-4913
Disclosure Date: December 15, 2019 (last updated November 27, 2024)
ZF2014-03 has a potential cross site scripting vector in multiple view helpers
0
Attacker Value
Unknown
CVE-2011-1939
Disclosure Date: November 26, 2019 (last updated November 27, 2024)
SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6.
0