Show filters
4,018 Total Results
Displaying 171-180 of 4,018
Sort by:
Attacker Value
Unknown
CVE-2023-46817
Disclosure Date: November 03, 2023 (last updated February 25, 2025)
An issue was discovered in phpFox before 4.8.14. The url request parameter passed to the /core/redirect route is not properly sanitized before being used in a call to the unserialize() PHP function. This can be exploited by remote, unauthenticated attackers to inject arbitrary PHP objects into the application scope, allowing them to perform a variety of attacks, such as executing arbitrary PHP code.
0
Attacker Value
Unknown
CVE-2022-4900
Disclosure Date: November 02, 2023 (last updated February 25, 2025)
A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow.
0
Attacker Value
Unknown
CVE-2023-5917
Disclosure Date: November 02, 2023 (last updated February 25, 2025)
A vulnerability, which was classified as problematic, has been found in phpBB up to 3.3.10. This issue affects the function main of the file phpBB/includes/acp/acp_icons.php of the component Smiley Pack Handler. The manipulation of the argument pak leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 3.3.11 is able to address this issue. The patch is named ccf6e6c255d38692d72fcb613b113e6eaa240aac. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-244307.
0
Attacker Value
Unknown
CVE-2023-5867
Disclosure Date: October 31, 2023 (last updated February 25, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.2.
0
Attacker Value
Unknown
CVE-2023-5866
Disclosure Date: October 31, 2023 (last updated February 25, 2025)
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository thorsten/phpmyfaq prior to 3.2.1.
0
Attacker Value
Unknown
CVE-2023-5865
Disclosure Date: October 31, 2023 (last updated February 25, 2025)
Insufficient Session Expiration in GitHub repository thorsten/phpmyfaq prior to 3.2.2.
0
Attacker Value
Unknown
CVE-2023-5864
Disclosure Date: October 31, 2023 (last updated February 25, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.1.
0
Attacker Value
Unknown
CVE-2023-5863
Disclosure Date: October 31, 2023 (last updated February 25, 2025)
Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.2.2.
0
Attacker Value
Unknown
CVE-2023-5199
Disclosure Date: October 30, 2023 (last updated February 25, 2025)
The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and including, 0.3 via the 'php-to-page' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to include local file and potentially execute code on the server. While subscribers may need to poison log files or otherwise get a file installed in order to achieve remote code execution, author and above users can upload files by default and achieve remote code execution easily.
0
Attacker Value
Unknown
CVE-2021-4418
Disclosure Date: October 20, 2023 (last updated February 25, 2025)
The Custom CSS, JS & PHP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.7. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to save code snippets via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0