Show filters
182 Total Results
Displaying 141-150 of 182
Sort by:
Attacker Value
Unknown

CVE-2018-5717

Disclosure Date: March 20, 2018 (last updated November 26, 2024)
Memory write mechanism in NCR S2 Dispenser controller before firmware version 0x0108 allows an unauthenticated user to upgrade or downgrade the firmware of the device, including to older versions with known vulnerabilities.
0
Attacker Value
Unknown

CVE-2017-18195

Disclosure Date: February 26, 2018 (last updated November 26, 2024)
An issue was discovered in tools/conversations/view_ajax.php in Concrete5 before 8.3.0. An unauthenticated user can enumerate comments from all blog posts by POSTing requests to /index.php/tools/required/conversations/view_ajax with incremental 'cnvID' integers.
Attacker Value
Unknown

CVE-2015-4721

Disclosure Date: September 07, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in Concrete5 5.7.3.1.
0
Attacker Value
Unknown

CVE-2015-4724

Disclosure Date: September 07, 2017 (last updated November 26, 2024)
SQL injection vulnerability in Concrete5 5.7.3.1.
0
Attacker Value
Unknown

CVE-2017-8082

Disclosure Date: April 24, 2017 (last updated November 26, 2024)
concrete5 8.1.0 has CSRF in Thumbnail Editor in the File Manager, which allows remote attackers to disable the entire installation by merely tricking an admin into viewing a malicious page involving the /tools/required/files/importers/imageeditor?fID=1&imgData= URI. This results in a site-wide denial of service making the site not accessible to any users or any administrators.
0
Attacker Value
Unknown

CVE-2017-7725

Disclosure Date: April 13, 2017 (last updated November 26, 2024)
concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a "canonical" URL on installation of concrete5 using the "Advanced Options" settings. Remote attackers can make a GET request with any domain name in the Host header; this is stored and allows for arbitrary domains to be set for certain links displayed to subsequent visitors, potentially an XSS vector.
Attacker Value
Unknown

CVE-2014-2960

Disclosure Date: April 10, 2017 (last updated November 26, 2024)
Vision Critical before 2014-05-30 allows attackers to read arbitrary files via unspecified vectors, as demonstrated by image files and configuration files.
0
Attacker Value
Unknown

CVE-2017-6905

Disclosure Date: March 15, 2017 (last updated November 26, 2024)
An issue was discovered in concrete5 <= 5.6.3.4. The vulnerability exists due to insufficient filtration of user-supplied data (disable_choose) passed to the "concrete5-legacy-master/web/concrete/tools/files/search_dialog.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
0
Attacker Value
Unknown

CVE-2017-6908

Disclosure Date: March 15, 2017 (last updated November 26, 2024)
An issue was discovered in concrete5 <= 5.6.3.4. The vulnerability exists due to insufficient filtration of user-supplied data (fID) passed to the "concrete5-legacy-master/web/concrete/tools/files/selector_data.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
0
Attacker Value
Unknown

CVE-2015-2250

Disclosure Date: May 15, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in concrete5 before 5.7.4 allow remote attackers to inject arbitrary web script or HTML via the (1) banned_word[] parameter to index.php/dashboard/system/conversations/bannedwords/success, (2) channel parameter to index.php/dashboard/reports/logs/view, (3) accessType parameter to index.php/tools/required/permissions/access_entity, (4) msCountry parameter to index.php/dashboard/system/multilingual/setup/load_icon, arHandle parameter to (5) design/submit or (6) design in index.php/ccm/system/dialogs/area/design/submit, (7) pageURL to index.php/dashboard/pages/single, (8) SEARCH_INDEX_AREA_METHOD parameter to index.php/dashboard/system/seo/searchindex/updated, (9) unit parameter to index.php/dashboard/system/optimization/jobs/job_scheduled, (10) register_notification_email parameter to index.php/dashboard/system/registration/open/1, or (11) PATH_INFO to index.php/dashboard/extend/connect/.
0