Show filters
140 Total Results
Displaying 101-110 of 140
Sort by:
Attacker Value
Unknown
CVE-2016-10901
Disclosure Date: August 21, 2019 (last updated November 27, 2024)
The wp-customer-reviews plugin before 3.0.9 for WordPress has XSS in the admin tools.
0
Attacker Value
Unknown
CVE-2016-10902
Disclosure Date: August 21, 2019 (last updated November 27, 2024)
The wp-customer-reviews plugin before 3.0.9 for WordPress has CSRF in the admin tools.
0
Attacker Value
Unknown
CVE-2018-20626
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
PHP Scripts Mall Consumer Reviews Script 4.0.3 has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory.
0
Attacker Value
Unknown
CVE-2018-20627
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
PHP Scripts Mall Consumer Reviews Script 4.0.3 has HTML injection via the search box.
0
Attacker Value
Unknown
CVE-2018-0603
Disclosure Date: June 26, 2018 (last updated November 26, 2024)
Cross-site scripting vulnerability in Site Reviews versions prior to 2.15.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2017-17614
Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Food Order Script 1.0 has SQL Injection via the /list city parameter.
0
Attacker Value
Unknown
CVE-2015-8965
Disclosure Date: April 06, 2017 (last updated November 26, 2024)
Rogue Wave JViews before 8.8 patch 21 and 8.9 before patch 1 allows remote attackers to execute arbitrary Java code that exists in the classpath, such as test code or administration code. The issue exists because the ilog.views.faces.IlvFacesController servlet in jviews-framework-all.jar does not require explicit configuration of servlets that can be called.
0
Attacker Value
Unknown
CVE-2015-7784
Disclosure Date: December 30, 2015 (last updated November 25, 2024)
SQL injection vulnerability in the BOKUBLOCK (1) BbAdminViewsControl213 plugin before 1.1 and (2) BbAdminViewsControl plugin before 2.1 for EC-CUBE allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-7226
Disclosure Date: September 17, 2015 (last updated October 05, 2023)
The Administration Views module 7.x-1.x before 7.x-1.5 for Drupal checks access permissions based on the router path from the view instead of the display property, which allows remote attackers to obtain sensitive information via vectors related to the access handler.
0
Attacker Value
Unknown
CVE-2015-5515
Disclosure Date: August 18, 2015 (last updated October 05, 2023)
The Views Bulk Operations (VBO) module 6.x-1.x and 7.x-3.x before 7.x-3.3 for Drupal, when the bulk operation for changing Roles is enabled, allows remote authenticated users to edit user accounts and add arbitrary roles to the accounts by leveraging access to a user account listing view with VBO enabled.
0