Show filters
242 Total Results
Displaying 171-180 of 242
Sort by:
Attacker Value
Unknown
CVE-2020-10567
Disclosure Date: March 14, 2020 (last updated February 21, 2025)
An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the name parameter, there is no validation of what kind of extension is sent. This makes it possible to execute PHP code if a legitimate JPEG image contains this code in the EXIF data, and the .php extension is used in the name parameter. (A potential fast patch is to disable the save_img action in the config file.)
0
Attacker Value
Unknown
CVE-2020-10212
Disclosure Date: March 07, 2020 (last updated February 21, 2025)
upload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is mishandled and because it is possible for a DNS hostname to resolve to an internal IP address. For example, an SSRF attempt may succeed if a .ico filename is added to the PATH_INFO. Also, an attacker could create a DNS hostname that resolves to the 0.0.0.0 IP address for DNS pinning. NOTE: this issue exists because of an incomplete fix for CVE-2018-14728.
0
Attacker Value
Unknown
CVE-2015-9487
Disclosure Date: October 11, 2019 (last updated November 27, 2024)
The ThemeMakers Almera Responsive Portfolio theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
0
Attacker Value
Unknown
CVE-2015-9488
Disclosure Date: October 11, 2019 (last updated November 27, 2024)
The ThemeMakers Almera Responsive Portfolio Site Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
0
Attacker Value
Unknown
CVE-2015-9486
Disclosure Date: October 11, 2019 (last updated November 27, 2024)
The ThemeMakers Axioma Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
0
Attacker Value
Unknown
CVE-2015-9489
Disclosure Date: October 11, 2019 (last updated November 27, 2024)
The ThemeMakers Goodnex Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
0
Attacker Value
Unknown
CVE-2015-9492
Disclosure Date: October 11, 2019 (last updated November 27, 2024)
The ThemeMakers SmartIT Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
0
Attacker Value
Unknown
CVE-2015-9491
Disclosure Date: October 11, 2019 (last updated November 27, 2024)
The ThemeMakers Blessing Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
0
Attacker Value
Unknown
CVE-2015-9484
Disclosure Date: October 11, 2019 (last updated November 27, 2024)
The ThemeMakers Accio One Page Parallax Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
0
Attacker Value
Unknown
CVE-2015-9485
Disclosure Date: October 11, 2019 (last updated November 27, 2024)
The ThemeMakers Accio Responsive Parallax One Page Site Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
0