Show filters
205 Total Results
Displaying 171-180 of 205
Sort by:
Attacker Value
Unknown

CVE-2019-10173

Disclosure Date: July 23, 2019 (last updated November 27, 2024)
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)
Attacker Value
Unknown

CVE-2018-14721

Disclosure Date: January 02, 2019 (last updated November 08, 2023)
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.
0
Attacker Value
Unknown

CVE-2018-14719

Disclosure Date: January 02, 2019 (last updated November 08, 2023)
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
Attacker Value
Unknown

CVE-2018-14718

Disclosure Date: January 02, 2019 (last updated November 08, 2023)
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
Attacker Value
Unknown

CVE-2018-14720

Disclosure Date: January 02, 2019 (last updated November 08, 2023)
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
0
Attacker Value
Unknown

CVE-2018-1000827

Disclosure Date: December 20, 2018 (last updated November 27, 2024)
Ubilling version <= 0.9.2 contains a Other/Unknown vulnerability in user-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution.
0
Attacker Value
Unknown

CVE-2018-11443

Disclosure Date: May 25, 2018 (last updated November 26, 2024)
The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0.
0
Attacker Value
Unknown

CVE-2018-11445

Disclosure Date: May 25, 2018 (last updated November 26, 2024)
A CSRF issue was discovered on the User Add/System Settings Page (system-settings-user-new2.php) in EasyService Billing 1.0. A User can be added with the Admin role.
0
Attacker Value
Unknown

CVE-2018-11444

Disclosure Date: May 25, 2018 (last updated November 26, 2024)
A SQL Injection issue was observed in the parameter "q" in jobcard-ongoing.php in EasyService Billing 1.0.
0
Attacker Value
Unknown

CVE-2018-11442

Disclosure Date: May 25, 2018 (last updated November 26, 2024)
A CSRF issue was discovered in EasyService Billing 1.0, which was triggered via a quotation-new3-new2.php?add=true&id= URI, as demonstrated by adding a new quotation.
0