Show filters
219 Total Results
Displaying 171-180 of 219
Sort by:
Attacker Value
Unknown
CVE-2019-15518
Disclosure Date: August 23, 2019 (last updated November 27, 2024)
Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler.
0
Attacker Value
Unknown
CVE-2019-14796
Disclosure Date: August 09, 2019 (last updated November 27, 2024)
The mq-woocommerce-products-price-bulk-edit (aka Woocommerce Products Price Bulk Edit) plugin 2.0 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=update_options show_products_page_limit parameter.
0
Attacker Value
Unknown
CVE-2019-14774
Disclosure Date: August 08, 2019 (last updated November 27, 2024)
The woo-variation-swatches (aka Variation Swatches for WooCommerce) plugin 1.0.61 for WordPress allows XSS via the wp-admin/admin.php?page=woo-variation-swatches-settings tab parameter.
0
Attacker Value
Unknown
CVE-2019-12890
Disclosure Date: June 19, 2019 (last updated November 27, 2024)
RedwoodHQ 2.5.5 does not require any authentication for database operations, which allows remote attackers to create admin users via a con.automationframework users insert_one call.
0
Attacker Value
Unknown
CVE-2019-7441
Disclosure Date: March 21, 2019 (last updated November 08, 2023)
cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.8 for WordPress allows Parameter Tampering in an amount parameter (such as amount_1), as demonstrated by purchasing an item for lower than the intended price. NOTE: The plugin author states it is true that the amount can be manipulated in the PayPal payment flow. However, the amount is validated against the WooCommerce order total before completing the order, and if it doesn’t match then the order will be left in an “On Hold” state
0
Attacker Value
Unknown
CVE-2019-9168
Disclosure Date: February 26, 2019 (last updated November 27, 2024)
WooCommerce before 3.5.5 allows XSS via a Photoswipe caption.
0
Attacker Value
Unknown
CVE-2018-20714
Disclosure Date: January 15, 2019 (last updated November 27, 2024)
The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability. This allows deletion of woocommerce.php, which leads to certain privilege checks not being in place, and therefore a shop manager can escalate privileges to admin.
0
Attacker Value
Unknown
CVE-2017-18356
Disclosure Date: January 15, 2019 (last updated October 18, 2024)
In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account that has at least Shop manager privileges. The attacker then constructs a specifically crafted string that will turn into a PHP object injection involving the includes/shortcodes/class-wc-shortcode-products.php WC_Shortcode_Products::get_products() use of cached queries within shortcodes.
0
Attacker Value
Unknown
CVE-2018-15503
Disclosure Date: August 18, 2018 (last updated November 27, 2024)
The unpack implementation in Swoole version 4.0.4 lacks correct size checks in the deserialization process. An attacker can craft a serialized object to exploit this vulnerability and cause a SEGV.
0
Attacker Value
Unknown
CVE-2017-16143
Disclosure Date: June 07, 2018 (last updated November 26, 2024)
commentapp.stetsonwood is an http server. commentapp.stetsonwood is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
0