Show filters
57 Total Results
Displaying 11-20 of 57
Sort by:
Attacker Value
Unknown

CVE-2021-36750

Disclosure Date: December 22, 2021 (last updated October 07, 2023)
ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names).
Attacker Value
Unknown

CVE-2021-27888

Disclosure Date: March 02, 2021 (last updated February 22, 2025)
ZendTo before 6.06-4 Beta allows XSS during the display of a drop-off in which a filename has unexpected characters.
Attacker Value
Unknown

CVE-2020-8984

Disclosure Date: March 24, 2020 (last updated February 21, 2025)
lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header.
Attacker Value
Unknown

CVE-2020-8986

Disclosure Date: March 24, 2020 (last updated February 21, 2025)
lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta failed to properly check for equality when validating the session cookie, allowing an attacker to gain administrative access with a large number of requests.
Attacker Value
Unknown

CVE-2020-8985

Disclosure Date: March 24, 2020 (last updated February 21, 2025)
ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality.
Attacker Value
Unknown

CVE-2014-8089

Disclosure Date: February 17, 2020 (last updated February 21, 2025)
SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands via a null byte.
Attacker Value
Unknown

CVE-2015-3154

Disclosure Date: January 27, 2020 (last updated February 21, 2025)
CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email.
Attacker Value
Unknown

CVE-2012-4451

Disclosure Date: January 03, 2020 (last updated February 21, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) Debug, (2) Feed\PubSubHubbub, (3) Log\Formatter\Xml, (4) Tag\Cloud\Decorator, (5) Uri, (6) View\Helper\HeadStyle, (7) View\Helper\Navigation\Sitemap, or (8) View\Helper\Placeholder\Container\AbstractStandalone, related to Escaper.
Attacker Value
Unknown

CVE-2014-4913

Disclosure Date: December 15, 2019 (last updated November 27, 2024)
ZF2014-03 has a potential cross site scripting vector in multiple view helpers
Attacker Value
Unknown

CVE-2011-1939

Disclosure Date: November 26, 2019 (last updated November 27, 2024)
SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6.