Show filters
251 Total Results
Displaying 101-110 of 251
Sort by:
Attacker Value
Unknown

CVE-2020-35597

Disclosure Date: June 16, 2022 (last updated February 23, 2025)
Victor CMS 1.0 is vulnerable to SQL injection via c_id parameter of admin_edit_comment.php, p_id parameter of admin_edit_post.php, u_id parameter of admin_edit_user.php, and edit parameter of admin_update_categories.php.
Attacker Value
Unknown

CVE-2022-21190

Disclosure Date: May 13, 2022 (last updated February 23, 2025)
This affects the package convict before 6.2.3. This is a bypass of [CVE-2022-22143](https://security.snyk.io/vuln/SNYK-JS-CONVICT-2340604). The [fix](https://github.com/mozilla/node-convict/commit/3b86be087d8f14681a9c889d45da7fe3ad9cd880) introduced, relies on the startsWith method and does not prevent the vulnerability: before splitting the path, it checks if it starts with __proto__ or this.constructor.prototype. To bypass this check it's possible to prepend the dangerous paths with any string value followed by a dot, like for example foo.__proto__ or foo.this.constructor.prototype.
Attacker Value
Unknown

CVE-2022-1013

Disclosure Date: May 09, 2022 (last updated February 23, 2025)
The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to a blind SQL injection vulnerability.
Attacker Value
Unknown

CVE-2022-22143

Disclosure Date: May 01, 2022 (last updated February 23, 2025)
The package convict before 6.2.2 are vulnerable to Prototype Pollution via the convict function due to missing validation of parentKey. **Note:** This vulnerability derives from an incomplete fix of another [vulnerability](https://security.snyk.io/vuln/SNYK-JS-CONVICT-1062508)
Attacker Value
Unknown

CVE-2022-28060

Disclosure Date: April 28, 2022 (last updated February 23, 2025)
SQL Injection vulnerability in Victor CMS v1.0, via the user_name parameter to /includes/login.php.
Attacker Value
Unknown

CVE-2022-1027

Disclosure Date: April 25, 2022 (last updated February 23, 2025)
The Page Restriction WordPress (WP) WordPress plugin before 1.2.7 allows bad actors with administrator privileges to the settings page to inject Javascript code to its settings leading to stored Cross-Site Scripting that will only affect administrator users.
Attacker Value
Unknown

CVE-2022-27478

Disclosure Date: April 21, 2022 (last updated February 23, 2025)
Victor v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component admin/profile.php?section=admin.
Attacker Value
Unknown

CVE-2022-26201

Disclosure Date: March 04, 2022 (last updated February 23, 2025)
Victor CMS v1.0 was discovered to contain a SQL injection vulnerability.
Attacker Value
Unknown

CVE-2022-23873

Disclosure Date: February 03, 2022 (last updated February 23, 2025)
Victor CMS v1.0 was discovered to contain a SQL injection vulnerability that allows attackers to inject arbitrary commands via 'user_firstname' parameter.
Attacker Value
Unknown

CVE-2021-46459

Disclosure Date: January 31, 2022 (last updated February 23, 2025)
Victor CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component admin/users.php?source=add_user. These vulnerabilities can be exploited through a crafted POST request via the user_name, user_firstname,user_lastname, or user_email parameters.