Show filters
140 Total Results
Displaying 101-110 of 140
Sort by:
Attacker Value
Unknown

CVE-2016-10901

Disclosure Date: August 21, 2019 (last updated November 27, 2024)
The wp-customer-reviews plugin before 3.0.9 for WordPress has XSS in the admin tools.
0
Attacker Value
Unknown

CVE-2016-10902

Disclosure Date: August 21, 2019 (last updated November 27, 2024)
The wp-customer-reviews plugin before 3.0.9 for WordPress has CSRF in the admin tools.
0
Attacker Value
Unknown

CVE-2018-20626

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
PHP Scripts Mall Consumer Reviews Script 4.0.3 has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory.
0
Attacker Value
Unknown

CVE-2018-20627

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
PHP Scripts Mall Consumer Reviews Script 4.0.3 has HTML injection via the search box.
0
Attacker Value
Unknown

CVE-2018-0603

Disclosure Date: June 26, 2018 (last updated November 26, 2024)
Cross-site scripting vulnerability in Site Reviews versions prior to 2.15.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2017-17614

Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Food Order Script 1.0 has SQL Injection via the /list city parameter.
0
Attacker Value
Unknown

CVE-2015-8965

Disclosure Date: April 06, 2017 (last updated November 26, 2024)
Rogue Wave JViews before 8.8 patch 21 and 8.9 before patch 1 allows remote attackers to execute arbitrary Java code that exists in the classpath, such as test code or administration code. The issue exists because the ilog.views.faces.IlvFacesController servlet in jviews-framework-all.jar does not require explicit configuration of servlets that can be called.
Attacker Value
Unknown

CVE-2015-7784

Disclosure Date: December 30, 2015 (last updated November 25, 2024)
SQL injection vulnerability in the BOKUBLOCK (1) BbAdminViewsControl213 plugin before 1.1 and (2) BbAdminViewsControl plugin before 2.1 for EC-CUBE allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-7226

Disclosure Date: September 17, 2015 (last updated October 05, 2023)
The Administration Views module 7.x-1.x before 7.x-1.5 for Drupal checks access permissions based on the router path from the view instead of the display property, which allows remote attackers to obtain sensitive information via vectors related to the access handler.
0
Attacker Value
Unknown

CVE-2015-5515

Disclosure Date: August 18, 2015 (last updated October 05, 2023)
The Views Bulk Operations (VBO) module 6.x-1.x and 7.x-3.x before 7.x-3.3 for Drupal, when the bulk operation for changing Roles is enabled, allows remote authenticated users to edit user accounts and add arbitrary roles to the accounts by leveraging access to a user account listing view with VBO enabled.
0