Show filters
191 Total Results
Displaying 141-150 of 191
Sort by:
Attacker Value
Unknown

CVE-2019-8437

Disclosure Date: March 07, 2019 (last updated November 27, 2024)
njiandan-cms through 2013-05-23 has index.php/admin/user_new CSRF to add an administrator.
0
Attacker Value
Unknown

CVE-2018-18799

Disclosure Date: November 16, 2018 (last updated November 27, 2024)
School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos.
0
Attacker Value
Unknown

CVE-2018-18797

Disclosure Date: November 16, 2018 (last updated November 27, 2024)
School Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php.
0
Attacker Value
Unknown

CVE-2017-6868

Disclosure Date: July 07, 2017 (last updated November 26, 2024)
An Improper Authentication issue was discovered in Siemens SIMATIC CP 44x-1 RNA, all versions prior to 1.4.1. An unauthenticated remote attacker may be able to perform administrative actions on the Communication Process (CP) of the RNA series module, if network access to Port 102/TCP is available and the configuration file for the CP is stored on the RNA's CPU.
0
Attacker Value
Unknown

CVE-2017-7242

Disclosure Date: March 23, 2017 (last updated November 26, 2024)
Multiple Cross-Site Scripting (XSS) were discovered in admin/modules components in SLiMS 7 Cendana through 2017-03-23: the keywords parameter to bibliography/checkout_item.php, bibliography/dl_print.php, bibliography/item.php, bibliography/item_barcode_generator.php, bibliography/printed_card.php, circulation/loan_rules.php, master_file/author.php, master_file/coll_type.php, and master_file/doc_language.php and the quickReturnID field to circulation/ajax_action.php.
0
Attacker Value
Unknown

CVE-2017-7202

Disclosure Date: March 21, 2017 (last updated November 26, 2024)
Multiple Cross-Site Scripting (XSS) were discovered in SLiMS 7 Cendana before 2017-03-16. The vulnerabilities exist due to insufficient filtration of user-supplied data (id) passed to the 'slims7_cendana-master/template/default/detail_template.php' and 'slims7_cendana-master/template/default-rtl/detail_template.php' URLs. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
0
Attacker Value
Unknown

CVE-2016-9343

Disclosure Date: February 13, 2017 (last updated November 26, 2024)
An issue was discovered in Rockwell Automation Logix5000 Programmable Automation Controller FRN 16.00 through 21.00 (excluding all firmware versions prior to FRN 16.00, which are not affected). By sending malformed common industrial protocol (CIP) packet, an attacker may be able to overflow a stack-based buffer and execute code on the controller or initiate a nonrecoverable fault resulting in a denial of service.
Attacker Value
Unknown

CVE-2016-9347

Disclosure Date: February 13, 2017 (last updated November 26, 2024)
An issue was discovered in Emerson SE4801T0X Redundant Wireless I/O Card V13.3, and SE4801T1X Simplex Wireless I/O Card V13.3. DeltaV Wireless I/O Cards (WIOC) running the firmware available in the DeltaV system, release v13.3, have the SSH (Secure Shell) functionality enabled unnecessarily.
0
Attacker Value
Unknown

CVE-2015-6469

Disclosure Date: September 26, 2015 (last updated October 05, 2023)
The interpreter in IBC Solar ServeMaster TLP+ and Danfoss TLX Pro+ allows remote attackers to discover script source code via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-6474

Disclosure Date: September 26, 2015 (last updated October 05, 2023)
IBC Solar ServeMaster TLP+ and Danfoss TLX Pro+ allow remote attackers to discover cleartext passwords by reading HTML source code.
0