Show filters
203 Total Results
Displaying 111-120 of 203
Sort by:
Attacker Value
Unknown
CVE-2019-13392
Disclosure Date: October 16, 2019 (last updated November 27, 2024)
A reflected Cross-Site Scripting (XSS) vulnerability in MindPalette NateMail 3.0.15 allows an attacker to execute remote JavaScript in a victim's browser via a specially crafted POST request. The application will reflect the recipient value if it is not in the NateMail recipient array. Note that this array is keyed via integers by default, so any string input will be invalid.
0
Attacker Value
Unknown
CVE-2019-13072
Disclosure Date: June 30, 2019 (last updated November 27, 2024)
Stored XSS in the Filters page (Name field) in ZoneMinder 1.32.3 allows a malicious user to embed and execute JavaScript code in the browser of any user who navigates to this page.
0
Attacker Value
Unknown
CVE-2019-9563
Disclosure Date: March 04, 2019 (last updated November 27, 2024)
In BlueMind 3.5.x before 3.5.11 Hotfix 7 and 4.x before 4.0-beta3, the contact application mishandles temporary uploads.
0
Attacker Value
Unknown
CVE-2019-8423
Disclosure Date: February 18, 2019 (last updated November 27, 2024)
ZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter.
0
Attacker Value
Unknown
CVE-2019-8427
Disclosure Date: February 18, 2019 (last updated November 27, 2024)
daemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters.
0
Attacker Value
Unknown
CVE-2019-8429
Disclosure Date: February 18, 2019 (last updated November 27, 2024)
ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php filter[Query][terms][0][cnj] parameter.
0
Attacker Value
Unknown
CVE-2019-8428
Disclosure Date: February 18, 2019 (last updated November 27, 2024)
ZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a newGroup[MonitorIds][] value.
0
Attacker Value
Unknown
CVE-2019-8426
Disclosure Date: February 18, 2019 (last updated November 27, 2024)
skins/classic/views/controlcap.php in ZoneMinder before 1.32.3 has XSS via the newControl array, as demonstrated by the newControl[MinTiltRange] parameter.
0
Attacker Value
Unknown
CVE-2019-8425
Disclosure Date: February 18, 2019 (last updated November 27, 2024)
includes/database.php in ZoneMinder before 1.32.3 has XSS in the construction of SQL-ERR messages.
0
Attacker Value
Unknown
CVE-2019-8424
Disclosure Date: February 18, 2019 (last updated November 27, 2024)
ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.
0