Show filters
252 Total Results
Displaying 161-170 of 252
Sort by:
Attacker Value
Unknown

CVE-2019-5957

Disclosure Date: May 17, 2019 (last updated November 27, 2024)
Untrusted search path vulnerability in Installer of Electronic reception and examination of application for radio licenses Online 1.0.9.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
0
Attacker Value
Unknown

CVE-2019-9567

Disclosure Date: March 04, 2019 (last updated November 27, 2024)
The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has XSS via a custom input field of a poll.
Attacker Value
Unknown

CVE-2019-9568

Disclosure Date: March 04, 2019 (last updated November 27, 2024)
The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has SQL Injection via the wp-admin/admin.php?page=forminator-entries entry[] parameter if the attacker has the delete permission.
Attacker Value
Unknown

CVE-2018-6866

Disclosure Date: February 23, 2018 (last updated November 26, 2024)
Cross Site Scripting (XSS) exists in PHP Scripts Mall Learning and Examination Management System Script 2.3.1 via a crafted message.
0
Attacker Value
Unknown

CVE-2017-17516

Disclosure Date: December 14, 2017 (last updated November 26, 2024)
scripts/inspect_webbrowser.py in Reddit Terminal Viewer (RTV) 1.19.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
0
Attacker Value
Unknown

CVE-2017-16792

Disclosure Date: November 13, 2017 (last updated November 26, 2024)
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb.
Attacker Value
Unknown

CVE-2017-14683

Disclosure Date: September 25, 2017 (last updated November 26, 2024)
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload.
Attacker Value
Unknown

CVE-2017-14506

Disclosure Date: September 25, 2017 (last updated November 26, 2024)
geminabox (aka Gem in a Box) before 0.13.6 has XSS, as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file.
Attacker Value
Unknown

CVE-2016-10369

Disclosure Date: May 08, 2017 (last updated November 08, 2023)
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).
0
Attacker Value
Unknown

CVE-2017-6356

Disclosure Date: March 20, 2017 (last updated November 26, 2024)
Palo Alto Networks Terminal Services (aka TS) Agent 6.0, 7.0, and 8.0 before 8.0.1 uses weak permissions for unspecified resources, which allows attackers to obtain sensitive session information via unknown vectors.