Show filters
219 Total Results
Displaying 171-180 of 219
Sort by:
Attacker Value
Unknown

CVE-2019-15518

Disclosure Date: August 23, 2019 (last updated November 27, 2024)
Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler.
0
Attacker Value
Unknown

CVE-2019-14796

Disclosure Date: August 09, 2019 (last updated November 27, 2024)
The mq-woocommerce-products-price-bulk-edit (aka Woocommerce Products Price Bulk Edit) plugin 2.0 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=update_options show_products_page_limit parameter.
Attacker Value
Unknown

CVE-2019-14774

Disclosure Date: August 08, 2019 (last updated November 27, 2024)
The woo-variation-swatches (aka Variation Swatches for WooCommerce) plugin 1.0.61 for WordPress allows XSS via the wp-admin/admin.php?page=woo-variation-swatches-settings tab parameter.
Attacker Value
Unknown

CVE-2019-12890

Disclosure Date: June 19, 2019 (last updated November 27, 2024)
RedwoodHQ 2.5.5 does not require any authentication for database operations, which allows remote attackers to create admin users via a con.automationframework users insert_one call.
0
Attacker Value
Unknown

CVE-2019-7441

Disclosure Date: March 21, 2019 (last updated November 08, 2023)
cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.8 for WordPress allows Parameter Tampering in an amount parameter (such as amount_1), as demonstrated by purchasing an item for lower than the intended price. NOTE: The plugin author states it is true that the amount can be manipulated in the PayPal payment flow. However, the amount is validated against the WooCommerce order total before completing the order, and if it doesn’t match then the order will be left in an “On Hold” state
0
Attacker Value
Unknown

CVE-2019-9168

Disclosure Date: February 26, 2019 (last updated November 27, 2024)
WooCommerce before 3.5.5 allows XSS via a Photoswipe caption.
0
Attacker Value
Unknown

CVE-2018-20714

Disclosure Date: January 15, 2019 (last updated November 27, 2024)
The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability. This allows deletion of woocommerce.php, which leads to certain privilege checks not being in place, and therefore a shop manager can escalate privileges to admin.
0
Attacker Value
Unknown

CVE-2017-18356

Disclosure Date: January 15, 2019 (last updated October 18, 2024)
In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account that has at least Shop manager privileges. The attacker then constructs a specifically crafted string that will turn into a PHP object injection involving the includes/shortcodes/class-wc-shortcode-products.php WC_Shortcode_Products::get_products() use of cached queries within shortcodes.
0
Attacker Value
Unknown

CVE-2018-15503

Disclosure Date: August 18, 2018 (last updated November 27, 2024)
The unpack implementation in Swoole version 4.0.4 lacks correct size checks in the deserialization process. An attacker can craft a serialized object to exploit this vulnerability and cause a SEGV.
0
Attacker Value
Unknown

CVE-2017-16143

Disclosure Date: June 07, 2018 (last updated November 26, 2024)
commentapp.stetsonwood is an http server. commentapp.stetsonwood is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
0