Show filters
233 Total Results
Displaying 171-180 of 233
Sort by:
Attacker Value
Unknown
CVE-2017-17691
Disclosure Date: September 07, 2018 (last updated November 27, 2024)
Homeputer CL Studio fur HomeMatic 4.0 Rel 160808 and earlier uses cleartext to exchange the username and password between server and client instances, which allows remote attackers to obtain sensitive information via a man in the middle attack.
0
Attacker Value
Unknown
CVE-2018-7213
Disclosure Date: March 11, 2018 (last updated November 26, 2024)
The Password Manager Extension in Abine Blur 7.8.242* before 7.8.2428 allows attackers to bypass the Multi-Factor Authentication and macOS disk-encryption protection mechanisms, and consequently exfiltrate secured data, because the right-click context menu is not secured.
0
Attacker Value
Unknown
CVE-2018-7469
Disclosure Date: February 28, 2018 (last updated November 26, 2024)
PHP Scripts Mall Entrepreneur Job Portal Script 2.0.9 has XSS via the p_name (aka Edit Category Name) field to admin/categories_industry.php (aka Categories - Industry Type).
0
Attacker Value
Unknown
CVE-2018-6863
Disclosure Date: February 12, 2018 (last updated November 26, 2024)
SQL Injection exists in PHP Scripts Mall Select Your College Script 2.0.2 via a Login Parameter.
0
Attacker Value
Unknown
CVE-2017-17648
Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Entrepreneur Dating Script 2.0.1 has SQL Injection via the search_result.php marital, gender, country, or profileid parameter.
0
Attacker Value
Unknown
CVE-2017-17596
Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Entrepreneur Job Portal Script 2.0.6 has SQL Injection via the jobsearch_all.php rid1 parameter.
0
Attacker Value
Unknown
CVE-2017-17595
Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter.
0
Attacker Value
Unknown
CVE-2017-17604
Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter.
0
Attacker Value
Unknown
CVE-2017-8866
Disclosure Date: December 11, 2017 (last updated November 26, 2024)
Elemental Path's CogniToys Dino smart toys through firmware version 0.0.794 share a fixed small pool of hardcoded keys, allowing a remote attacker to use a different Dino device to decrypt VoIP traffic between a child's Dino and remote server.
0
Attacker Value
Unknown
CVE-2017-8865
Disclosure Date: December 11, 2017 (last updated November 26, 2024)
Elemental Path's CogniToys Dino smart toys through firmware version 0.0.794 do not provide sufficient protections against capture-replay attacks, allowing an attacker on the network to replay VoIP traffic between a Dino device and remote server to any other Dino device.
0