Show filters
301 Total Results
Displaying 131-140 of 301
Sort by:
Attacker Value
Unknown

Telos Automated Message Handling System reflected XSS in prefs.asp

Disclosure Date: January 03, 2020 (last updated February 21, 2025)
: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in prefs.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5.
Attacker Value
Unknown

Telos Automated Message Handling System reflected XSS in ModalWindowPopup.asp

Disclosure Date: January 03, 2020 (last updated February 21, 2025)
: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ModalWindowPopup.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5.
Attacker Value
Unknown

Telos Automated Message Handling System information disclosure in itemlookup.asp

Disclosure Date: January 03, 2020 (last updated February 21, 2025)
: Information Exposure vulnerability in itemlookup.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5.
Attacker Value
Unknown

Telos Automated Message Handling System reflected XSS in uploaditem.asp

Disclosure Date: January 03, 2020 (last updated February 21, 2025)
: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uploaditem.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5.
Attacker Value
Unknown

Telos Automated Message Handling System reflected XSS in itemlookup.asp

Disclosure Date: January 03, 2020 (last updated February 21, 2025)
: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in itemlookup.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5.
Attacker Value
Unknown

CVE-2016-5285

Disclosure Date: November 15, 2019 (last updated November 27, 2024)
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.
Attacker Value
Unknown

CVE-2019-16251

Disclosure Date: October 31, 2019 (last updated November 27, 2024)
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
Attacker Value
Unknown

CVE-2019-17526

Disclosure Date: October 18, 2019 (last updated November 08, 2023)
An issue was discovered in SageMath Sage Cell Server through 2019-10-05. Python Code Injection can occur in the context of an internet facing web application. Malicious actors can execute arbitrary commands on the underlying operating system, as demonstrated by an __import__('os').popen('whoami').read() line. NOTE: the vendor's position is that the product is "vulnerable by design" and the current behavior will be retained
Attacker Value
Unknown

CVE-2015-9477

Disclosure Date: October 10, 2019 (last updated November 27, 2024)
The Vernissage theme 1.2.8 for WordPress has insufficient restrictions on option updates.
Attacker Value
Unknown

CVE-2019-12751

Disclosure Date: July 11, 2019 (last updated November 27, 2024)
Symantec Messaging Gateway, prior to 10.7.1, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
0