Show filters
563 Total Results
Displaying 151-160 of 563
Sort by:
Attacker Value
Unknown

CVE-2022-23507

Disclosure Date: December 15, 2022 (last updated February 24, 2025)
Tendermint is a high-performance blockchain consensus engine for Byzantine fault tolerant applications. Versions prior to 0.28.0 contain a potential attack via Improper Verification of Cryptographic Signature, affecting anyone using the tendermint-light-client and related packages to perform light client verification (e.g. IBC-rs, Hermes). The light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. This issue is patched in version 0.28.0. There are no workarounds.
Attacker Value
Unknown

CVE-2022-45769

Disclosure Date: December 05, 2022 (last updated February 24, 2025)
A cross-site scripting (XSS) vulnerability in ClicShopping_V3 v3.402 allows attackers to execute arbitrary web scripts or HTML via a crafted URL parameter.
Attacker Value
Unknown

CVE-2022-39397

Disclosure Date: November 22, 2022 (last updated February 24, 2025)
aliyun-oss-client is a rust client for Alibaba Cloud OSS. Users of this library will be affected, the incoming secret will be disclosed unintentionally. This issue has been patched in version 0.8.1.
Attacker Value
Unknown

CVE-2022-44001

Disclosure Date: November 17, 2022 (last updated February 24, 2025)
An issue was discovered in BACKCLICK Professional 5.9.63. User authentication for accessing the CORBA back-end services can be bypassed.
Attacker Value
Unknown

CVE-2022-44005

Disclosure Date: November 16, 2022 (last updated February 24, 2025)
An issue was discovered in BACKCLICK Professional 5.9.63. Due to the use of consecutive IDs in verification links, the newsletter sign-up functionality is vulnerable to the enumeration of subscribers' e-mail addresses. Furthermore, it is possible to subscribe and verify other persons' e-mail addresses to newsletters without their consent.
Attacker Value
Unknown

CVE-2022-44000

Disclosure Date: November 16, 2022 (last updated February 24, 2025)
An issue was discovered in BACKCLICK Professional 5.9.63. Due to an exposed internal communications interface, it is possible to execute arbitrary system commands on the server.
Attacker Value
Unknown

CVE-2022-44006

Disclosure Date: November 16, 2022 (last updated February 24, 2025)
An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames, an externally reachable, unauthenticated update function permits writing files outside the intended target location. Achieving remote code execution is possible, e.g., by uploading an executable file.
Attacker Value
Unknown

CVE-2022-44004

Disclosure Date: November 16, 2022 (last updated February 24, 2025)
An issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of authentication, unauthenticated attackers can complete the password-reset process for any account and set a new password.
Attacker Value
Unknown

CVE-2022-44002

Disclosure Date: November 16, 2022 (last updated February 24, 2025)
An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient output encoding of user-supplied data, the web application is vulnerable to cross-site scripting (XSS) at various locations.
Attacker Value
Unknown

CVE-2022-44003

Disclosure Date: November 16, 2022 (last updated February 24, 2025)
An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the application is vulnerable to SQL injection at various locations.