Show filters
597 Total Results
Displaying 161-170 of 597
Sort by:
Attacker Value
Unknown
CVE-2022-2987
Disclosure Date: September 26, 2022 (last updated February 24, 2025)
The Ldap WP Login / Active Directory Integration WordPress plugin before 3.0.2 does not have any authorisation and CSRF checks when updating it's settings (which are hooked to the init action), allowing unauthenticated attackers to update them. Attackers could set their own LDAP server to be used to authenticated users, therefore bypassing the current authentication
0
Attacker Value
Unknown
CVE-2022-2265
Disclosure Date: September 21, 2022 (last updated February 24, 2025)
The Identity and Directory Management System developed by Çekino Bilgi Teknolojileri before version 2.1.25 has an unauthenticated Path traversal vulnerability. This has been fixed in the version 2.1.25
0
Attacker Value
Unknown
CVE-2022-1697
Disclosure Date: September 06, 2022 (last updated February 24, 2025)
Okta Active Directory Agent versions 3.8.0 through 3.11.0 installed the Okta AD Agent Update Service using an unquoted path. Note: To remediate this vulnerability, you must uninstall Okta Active Directory Agent and reinstall Okta Active Directory Agent 3.12.0 or greater per the documentation.
0
Attacker Value
Unknown
CVE-2022-2072
Disclosure Date: July 25, 2022 (last updated February 24, 2025)
The Name Directory WordPress plugin before 1.25.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting. Furthermore, as the payload is also saved into the database after the request, it leads to a Stored XSS as well
0
Attacker Value
Unknown
CVE-2022-2071
Disclosure Date: July 25, 2022 (last updated February 24, 2025)
The Name Directory WordPress plugin before 1.25.4 does not have CSRF check when importing names, and is also lacking sanitisation as well as escaping in some of the imported data, which could allow attackers to make a logged in admin import arbitrary names with XSS payloads in them.
0
Attacker Value
Unknown
CVE-2022-31384
Disclosure Date: June 16, 2022 (last updated February 23, 2025)
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php.
0
Attacker Value
Unknown
CVE-2022-31383
Disclosure Date: June 16, 2022 (last updated February 23, 2025)
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.
0
Attacker Value
Unknown
CVE-2022-31382
Disclosure Date: June 16, 2022 (last updated February 23, 2025)
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php.
0
Attacker Value
Unknown
CVE-2022-1949
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any remote unauthenticated user to issue a filter that allows searching for database items they do not have access to, including but not limited to potentially userPassword hashes and other sensitive data.
0
Attacker Value
Unknown
CVE-2022-28531
Disclosure Date: May 20, 2022 (last updated February 23, 2025)
Sourcecodester Covid-19 Directory on Vaccination System1.0 is vulnerable to SQL Injection via the admin/login.php txtusername (aka Username) field.
0