Show filters
180 Total Results
Displaying 111-120 of 180
Sort by:
Attacker Value
Unknown

CVE-2020-6215

Disclosure Date: April 14, 2020 (last updated February 21, 2025)
SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, allows an attacker to redirect users to a malicious site due to insufficient URL validation and steal credentials of the victim, leading to URL Redirection vulnerability.
Attacker Value
Unknown

CVE-2020-6217

Disclosure Date: April 14, 2020 (last updated February 21, 2025)
SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.
Attacker Value
Unknown

CVE-2020-6229

Disclosure Date: April 14, 2020 (last updated February 21, 2025)
SAP NetWeaver AS ABAP (Business Server Pages application CRM_BSP_FRAME), versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not sufficiently encode user controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.
Attacker Value
Unknown

CVE-2020-6205

Disclosure Date: March 10, 2020 (last updated February 21, 2025)
SAP NetWeaver AS ABAP Business Server Pages (Smart Forms), SAP_BASIS versions- 7.00, 7.01, 7.02, 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, 7.51, 7.52, 7.53, 7.54; does not sufficiently encode user controlled inputs, allowing an unauthenticated attacker to non-permanently deface or modify displayed content and/or steal authentication information of the user and/or impersonate the user and access all information with the same rights as the target user, leading to Reflected Cross Site Scripting Vulnerability.
Attacker Value
Unknown

CVE-2014-3445

Disclosure Date: January 28, 2020 (last updated February 21, 2025)
backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows remote attackers to bypass authentication by leveraging knowledge of the administrator password hash.
Attacker Value
Unknown

CVE-2011-4943

Disclosure Date: January 22, 2020 (last updated November 28, 2024)
ImpressPages CMS v1.0.12 has Unspecified Remote Code Execution (fixed in v1.0.13)
Attacker Value
Unknown

CVE-2015-9428

Disclosure Date: September 26, 2019 (last updated November 27, 2024)
The wplegalpages plugin before 1.1 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=legal-pages lp-domain-name, lp-business-name, lp-phone, lp-street, lp-city-state, lp-country, lp-email, lp-address, or lp-niche parameters.
Attacker Value
Unknown

CVE-2017-18586

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The insert-pages plugin before 3.2.4 for WordPress has directory traversal via custom template paths.
0
Attacker Value
Unknown

CVE-2018-20967

Disclosure Date: August 14, 2019 (last updated November 27, 2024)
The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.
0
Attacker Value
Unknown

CVE-2016-10883

Disclosure Date: August 14, 2019 (last updated November 27, 2024)
The simple-add-pages-or-posts plugin before 1.7 for WordPress has CSRF for deleting users.
0