Show filters
203 Total Results
Displaying 111-120 of 203
Sort by:
Attacker Value
Unknown

CVE-2019-13392

Disclosure Date: October 16, 2019 (last updated November 27, 2024)
A reflected Cross-Site Scripting (XSS) vulnerability in MindPalette NateMail 3.0.15 allows an attacker to execute remote JavaScript in a victim's browser via a specially crafted POST request. The application will reflect the recipient value if it is not in the NateMail recipient array. Note that this array is keyed via integers by default, so any string input will be invalid.
Attacker Value
Unknown

CVE-2019-13072

Disclosure Date: June 30, 2019 (last updated November 27, 2024)
Stored XSS in the Filters page (Name field) in ZoneMinder 1.32.3 allows a malicious user to embed and execute JavaScript code in the browser of any user who navigates to this page.
Attacker Value
Unknown

CVE-2019-9563

Disclosure Date: March 04, 2019 (last updated November 27, 2024)
In BlueMind 3.5.x before 3.5.11 Hotfix 7 and 4.x before 4.0-beta3, the contact application mishandles temporary uploads.
0
Attacker Value
Unknown

CVE-2019-8423

Disclosure Date: February 18, 2019 (last updated November 27, 2024)
ZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter.
0
Attacker Value
Unknown

CVE-2019-8427

Disclosure Date: February 18, 2019 (last updated November 27, 2024)
daemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters.
0
Attacker Value
Unknown

CVE-2019-8429

Disclosure Date: February 18, 2019 (last updated November 27, 2024)
ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php filter[Query][terms][0][cnj] parameter.
0
Attacker Value
Unknown

CVE-2019-8428

Disclosure Date: February 18, 2019 (last updated November 27, 2024)
ZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a newGroup[MonitorIds][] value.
0
Attacker Value
Unknown

CVE-2019-8426

Disclosure Date: February 18, 2019 (last updated November 27, 2024)
skins/classic/views/controlcap.php in ZoneMinder before 1.32.3 has XSS via the newControl array, as demonstrated by the newControl[MinTiltRange] parameter.
0
Attacker Value
Unknown

CVE-2019-8425

Disclosure Date: February 18, 2019 (last updated November 27, 2024)
includes/database.php in ZoneMinder before 1.32.3 has XSS in the construction of SQL-ERR messages.
0
Attacker Value
Unknown

CVE-2019-8424

Disclosure Date: February 18, 2019 (last updated November 27, 2024)
ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.
0