Show filters
175 Total Results
Displaying 111-120 of 175
Sort by:
Attacker Value
Unknown
CVE-2020-28994
Disclosure Date: November 24, 2020 (last updated February 22, 2025)
A SQL injection vulnerability was discovered in Karenderia Multiple Restaurant System, affecting versions 5.4.2 and below. The vulnerability allows for an unauthenticated attacker to perform various tasks such as modifying and leaking all contents of the database.
0
Attacker Value
Unknown
CVE-2020-7032
Disclosure Date: November 12, 2020 (last updated February 22, 2025)
An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. Affected versions of Avaya WebLM include: 7.0 through 7.1.3.6 and 8.0 through 8.1.2.
0
Attacker Value
Unknown
CVE-2020-7029
Disclosure Date: August 11, 2020 (last updated February 21, 2025)
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface Web component of Avaya Aura Communication Manager and Avaya Aura Messaging. This vulnerability could allow an unauthenticated remote attacker to perform Web administration actions with the privileged level of the authenticated user. Affected versions of Communication Manager are 7.0.x, 7.1.x prior to 7.1.3.5 and 8.0.x. Affected versions of Messaging are 7.0.x, 7.1 and 7.1 SP1.
0
Attacker Value
Unknown
CVE-2019-17603
Disclosure Date: June 02, 2020 (last updated February 21, 2025)
Ene.sys in Asus Aura Sync through 1.07.71 does not properly validate input to IOCTL 0x80102044, 0x80102050, and 0x80102054, which allows local users to cause a denial of service (system crash) or gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption.
0
Attacker Value
Unknown
CVE-2019-7007
Disclosure Date: February 28, 2020 (last updated February 21, 2025)
A directory traversal vulnerability has been found in the Avaya Equinox Management(iView)versions R9.1.9.0 and earlier. Successful exploitation could potentially allow an unauthenticated attacker to access files that are outside the restricted directory on the remote server.
0
Attacker Value
Unknown
CVE-2016-5285
Disclosure Date: November 15, 2019 (last updated November 27, 2024)
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.
0
Attacker Value
Unknown
CVE-2019-18416
Disclosure Date: October 24, 2019 (last updated November 27, 2024)
Sourcecodester Restaurant Management System 1.0 allows XSS via the Last Name field of a member.
0
Attacker Value
Unknown
CVE-2019-18417
Disclosure Date: October 24, 2019 (last updated November 27, 2024)
Sourcecodester Restaurant Management System 1.0 allows an authenticated attacker to upload arbitrary files that can result in code execution. The issue occurs because the application fails to adequately sanitize user-supplied input, e.g., "add a new food" allows .php files.
0
Attacker Value
Unknown
CVE-2019-18414
Disclosure Date: October 24, 2019 (last updated November 27, 2024)
Sourcecodester Restaurant Management System 1.0 is affected by an admin/staff-exec.php Cross Site Request Forgery vulnerability due to a lack of CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code or adding a staff entry via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2019-18415
Disclosure Date: October 24, 2019 (last updated November 27, 2024)
Sourcecodester Restaurant Management System 1.0 allows XSS via the "send a message" screen.
0