Show filters
148 Total Results
Displaying 111-120 of 148
Sort by:
Attacker Value
Unknown
CVE-2012-4230
Disclosure Date: April 25, 2014 (last updated October 05, 2023)
The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the TinyMCE security policy for the (1) encoding directive and (2) valid_elements attribute, which allows attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors, as demonstrated using a textarea element.
0
Attacker Value
Unknown
CVE-2012-3414
Disclosure Date: July 19, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.
0
Attacker Value
Unknown
CVE-2013-2204
Disclosure Date: July 08, 2013 (last updated October 05, 2023)
moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider the presence of a # (pound sign) character during extraction of the QUERY_STRING, which allows remote attackers to pass arbitrary parameters to a Flash application, and conduct content-spoofing attacks, via a crafted string after a ? (question mark) character.
0
Attacker Value
Unknown
CVE-2013-0136
Disclosure Date: June 01, 2013 (last updated October 05, 2023)
Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow remote authenticated users to upload and execute arbitrary programs, read arbitrary files, or cause a denial of service (file deletion or renaming) via (1) the uploadPath parameter in an UPLOAD operation; the paths[] parameter in a (2) DELETE, (3) CUT, or (4) COPY operation; or the newPath parameter in a (5) CUT or (6) COPY operation.
0
Attacker Value
Unknown
CVE-2012-6112
Disclosure Date: January 27, 2013 (last updated October 05, 2023)
classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 and other products, does not properly handle control characters, which allows remote attackers to trigger arbitrary outbound HTTP requests via a crafted string.
0
Attacker Value
Unknown
CVE-2012-3001
Disclosure Date: October 22, 2012 (last updated October 05, 2023)
Mutiny Standard before 4.5-1.12 allows remote attackers to execute arbitrary commands via the network-interface menu, related to a "command injection vulnerability."
0
Attacker Value
Unknown
CVE-2012-5347
Disclosure Date: October 09, 2012 (last updated October 05, 2023)
TinyWebGallery 1.8.3 allows remote attackers to execute arbitrary code via shell metacharacters in the command parameter to (1) inc/filefunctions.inc or (2) info.php.
0
Attacker Value
Unknown
CVE-2012-1409
Disclosure Date: March 14, 2012 (last updated October 04, 2023)
Unspecified vulnerability in the Tiny Password (com.tinycouch.android.freepassword) application 1.64 for Android has unknown impact and attack vectors.
0
Attacker Value
Unknown
CVE-2011-4825
Disclosure Date: December 15, 2011 (last updated October 04, 2023)
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters.
0
Attacker Value
Unknown
CVE-2011-3810
Disclosure Date: September 24, 2011 (last updated October 04, 2023)
TinyWebGallery (TWG) 1.8.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by i_frames/i_register.php.
0