Show filters
333 Total Results
Displaying 151-160 of 333
Sort by:
Attacker Value
Unknown
CVE-2022-27330
Disclosure Date: May 03, 2022 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_product of E-Commerce Website v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Title text field.
0
Attacker Value
Unknown
CVE-2022-24864
Disclosure Date: April 20, 2022 (last updated February 23, 2025)
Origin Protocol is a blockchain based project. The Origin Protocol project website allows for malicious users to inject malicious Javascript via a POST request to `/presale/join`. User-controlled data is passed with no sanitization to SendGrid and injected into an email that is delivered to the founders@originprotocol.com. If the email recipient is using an email program that is susceptible to XSS, then that email recipient will receive an email that may contain malicious XSS. Regardless if the email recipient’s mail program has vulnerabilities or not, the hacker can at the very least inject malicious HTML that modifies the body content of the email. There are currently no known workarounds.
0
Attacker Value
Unknown
CVE-2022-1329
Disclosure Date: April 19, 2022 (last updated February 23, 2025)
The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to obtain remote code execution, in versions 3.6.0 to 3.6.2.
0
Attacker Value
Unknown
CVE-2022-27357
Disclosure Date: April 08, 2022 (last updated February 23, 2025)
Ecommerce-Website v1 was discovered to contain an arbitrary file upload vulnerability via /customer_register.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
0
Attacker Value
Unknown
CVE-2022-27346
Disclosure Date: April 08, 2022 (last updated February 23, 2025)
Ecommece-Website v1.1.0 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?slides. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
0
Attacker Value
Unknown
CVE-2022-26615
Disclosure Date: April 05, 2022 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability in College Website Content Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the User Profile Name text fields.
0
Attacker Value
Unknown
CVE-2022-27436
Disclosure Date: April 04, 2022 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_user at Ecommerce-Website v1.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username text field.
0
Attacker Value
Unknown
CVE-2022-27435
Disclosure Date: April 04, 2022 (last updated February 23, 2025)
An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to upload a webshell via the Product Image component.
0
Attacker Value
Unknown
CVE-2022-1078
Disclosure Date: March 29, 2022 (last updated February 23, 2025)
A vulnerability was found in SourceCodester College Website Management System 1.0. It has been classified as critical. Affected is the file /cwms/admin/?page=articles/view_article/. The manipulation of the argument id with the input ' and (select * from(select(sleep(10)))Avx) and 'abc' = 'abc with an unknown input leads to sql injection. It is possible to launch the attack remotely and without authentication.
0
Attacker Value
Unknown
CVE-2022-1075
Disclosure Date: March 29, 2022 (last updated February 23, 2025)
A vulnerability was found in College Website Management System 1.0 and classified as problematic. Affected by this issue is the file /cwms/classes/Master.php?f=save_contact of the component Contact Handler. The manipulation leads to persistent cross site scripting. The attack may be launched remotely and requires authentication.
0