Show filters
180 Total Results
Displaying 151-160 of 180
Sort by:
Attacker Value
Unknown

CVE-2015-4065

Disclosure Date: May 27, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in shared/shortcodes/inbound-shortcodes.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the post parameter to wp-admin/post-new.php.
0
Attacker Value
Unknown

CVE-2014-9176

Disclosure Date: December 02, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the InstaSqueeze Sexy Squeeze Pages plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter to lp/index.php.
0
Attacker Value
Unknown

CVE-2014-9024

Disclosure Date: November 20, 2014 (last updated October 05, 2023)
The Protected Pages module 7.x-2.x before 7.x-2.4 for Drupal allows remote attackers to bypass the password protection via a crafted path.
0
Attacker Value
Unknown

CVE-2014-5857

Disclosure Date: September 10, 2014 (last updated October 05, 2023)
The White & Yellow Pages (aka com.avantar.wny) application 5.1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-5758

Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The Yellow Pages Local Search (aka com.yellowbook.android2) application 11.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-3011

Disclosure Date: June 27, 2014 (last updated October 05, 2023)
IBM OpenPages GRC Platform 6.1.0.1 before IF4 allows remote attackers to conduct link injection attacks via unspecified vectors.
0
Attacker Value
Unknown

CVE-2011-1381

Disclosure Date: June 27, 2014 (last updated October 05, 2023)
Unspecified vulnerability in IBM OpenPages GRC Platform 6.1.0.1 before IF4 allows remote attackers to bypass intended access restrictions via unknown vectors.
0
Attacker Value
Unknown

CVE-2013-4595

Disclosure Date: June 09, 2014 (last updated October 05, 2023)
The Secure Pages module 6.x-2.x before 6.x-2.0 for Drupal does not properly match URLs, which causes HTTP to be used instead of HTTPS and makes it easier for remote attackers to obtain sensitive information via a crafted web page.
0
Attacker Value
Unknown

CVE-2014-1252

Disclosure Date: January 24, 2014 (last updated October 05, 2023)
Double free vulnerability in Apple Pages 2.x before 2.1 and 5.x before 5.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Word file.
0
Attacker Value
Unknown

CVE-2013-6111

Disclosure Date: November 02, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the mod_pagespeed module 0.x, 1.0.22.7, 1.1.x, 1.24.1, 1.3.25.1 through 1.3.25.4, 1.4.26.1 through 1.4.26.4, 1.5.27.1 through 1.5.27.3, and 1.6.29.1 through 1.6.29.6 for the Apache HTTP Server allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0