Show filters
597 Total Results
Displaying 111-120 of 597
Sort by:
Attacker Value
Unknown
CVE-2022-33161
Disclosure Date: October 14, 2023 (last updated October 19, 2023)
IBM Security Directory Server 6.4.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. X-Force ID: 228569.
0
Attacker Value
Unknown
CVE-2022-32755
Disclosure Date: October 14, 2023 (last updated October 19, 2023)
IBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 228505.
0
Attacker Value
Unknown
CVE-2022-33160
Disclosure Date: October 06, 2023 (last updated October 11, 2023)
IBM Security Directory Suite 8.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 228568.
0
Attacker Value
Unknown
CVE-2023-4506
Disclosure Date: September 27, 2023 (last updated October 08, 2023)
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 4.1.10. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with administrative access and above, to change the LDAP server and retrieve the credentials for the original LDAP server.
0
Attacker Value
Unknown
CVE-2023-4505
Disclosure Date: September 27, 2023 (last updated October 08, 2023)
The Staff / Employee Business Directory for Active Directory plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 1.2.3. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with administrative access and above, to change the LDAP server and retrieve the credentials for the original LDAP server.
0
Attacker Value
Unknown
CVE-2022-33164
Disclosure Date: September 08, 2023 (last updated October 08, 2023)
IBM Security Directory Server 7.2.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view or write to arbitrary files on the system. IBM X-Force ID: 228579.
0
Attacker Value
Unknown
CVE-2023-2813
Disclosure Date: September 04, 2023 (last updated October 08, 2023)
All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite WordPress theme before 2.1, Cafe Bistro WordPress theme before 1.1.4, College WordPress theme before 1.5.1, Connections Reloaded WordPress theme through 3.1, Counterpoint WordPress theme through 1.8.1, Digitally WordPress theme through 1.0.8, Directory WordPress theme before 3.0.2, Drop WordPress theme before 1.22, Everse WordPress theme before 1.2.4, Fashionable Store WordPress theme through 1.3.4, Fullbase WordPress theme before 1.2.1, Ilex WordPress theme before 1.4.2, Js O3 Lite WordPress theme through 1.5.8.2, Js Paper WordPress theme through 2.5.7, Kata WordPress theme before 1.2.9, Kata App WordPress theme through 1.0.5, Kata Business WordPress theme through 1.0.2, Looki …
0
Attacker Value
Unknown
CVE-2023-2279
Disclosure Date: August 31, 2023 (last updated November 09, 2023)
The WP Directory Kit plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation on the 'admin_page_display' function. This makes it possible for unauthenticated attackers to delete or change plugin settings, import demo data, modify or delete Directory Kit related posts and terms via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Partial patches were made avilable in versions 1.2.0 and 1.2.1 but the issue was not fully patched until 1.2.2
0
Attacker Value
Unknown
CVE-2023-41539
Disclosure Date: August 30, 2023 (last updated October 08, 2023)
phpjabbers Business Directory Script 3.2 is vulnerable to SQL Injection via the column parameter.
0
Attacker Value
Unknown
CVE-2023-41537
Disclosure Date: August 30, 2023 (last updated October 08, 2023)
phpjabbers Business Directory Script 3.2 is vulnerable to Cross Site Scripting (XSS) via the keyword parameter.
0