Show filters
597 Total Results
Displaying 151-160 of 597
Sort by:
Attacker Value
Unknown

CVE-2023-1055

Disclosure Date: February 27, 2023 (last updated October 08, 2023)
A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker with a local account where the cockpit-389-ds is running can list the processes and display the hashed passwords. The highest threat from this vulnerability is to data confidentiality.
Attacker Value
Unknown

CVE-2023-0278

Disclosure Date: February 27, 2023 (last updated October 08, 2023)
The GeoDirectory WordPress plugin before 2.2.24 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
Attacker Value
Unknown

CVE-2022-4775

Disclosure Date: January 23, 2023 (last updated October 08, 2023)
The GeoDirectory WordPress plugin before 2.2.22 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Attacker Value
Unknown

CVE-2023-23749

Disclosure Date: January 17, 2023 (last updated October 08, 2023)
The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Injection since is not properly sanitizing the 'username' POST parameter. An attacker can manipulate this paramter to dump arbitrary contents form the LDAP Database.
Attacker Value
Unknown

CVE-2022-46096

Disclosure Date: December 21, 2022 (last updated February 24, 2025)
A Cross site scripting (XSS) vulnerability in Sourcecodester Online Covid-19 Directory on Vaccination System v1.0 allows attackers to execute arbitrary code via the txtfullname parameter or txtphone parameter to register.php without logging in.
Attacker Value
Unknown

CVE-2022-46095

Disclosure Date: December 21, 2022 (last updated February 24, 2025)
Sourcecodester Covid-19 Directory on Vaccination System 1.0 was discovered to contain a Cross-Site Scripting (XSS) vulnerability via verification.php because the program does not verify the txtvaccinationID parameter.
Attacker Value
Unknown

CVE-2022-45010

Disclosure Date: December 07, 2022 (last updated February 24, 2025)
Simple Phone Book/Directory Web App v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter at /PhoneBook/edit.php.
Attacker Value
Unknown

CVE-2022-36179

Disclosure Date: November 22, 2022 (last updated February 24, 2025)
Fusiondirectory 1.3 suffers from Improper Session Handling.
Attacker Value
Unknown

CVE-2022-36180

Disclosure Date: November 22, 2022 (last updated February 24, 2025)
Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fusiondirectory/index.php?message=invalidparameter&plug={Injection], /fusiondirectory/index.php?signout=1&message=[injection]&plug=106.
Attacker Value
Unknown

CVE-2022-2850

Disclosure Date: October 14, 2022 (last updated February 24, 2025)
A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514.