Show filters
732 Total Results
Displaying 181-190 of 732
Sort by:
Attacker Value
Unknown
CVE-2022-23518
Disclosure Date: December 14, 2022 (last updated February 24, 2025)
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Versions >= 1.0.3, < 1.4.4 are vulnerable to cross-site scripting via data URIs when used in combination with Loofah >= 2.1.0. This issue is patched in version 1.4.4.
0
Attacker Value
Unknown
CVE-2022-23517
Disclosure Date: December 14, 2022 (last updated February 24, 2025)
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Certain configurations of rails-html-sanitizer < 1.4.4 use an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service through CPU resource consumption. This issue has been patched in version 1.4.4.
0
Attacker Value
Unknown
CVE-2022-23499
Disclosure Date: December 13, 2022 (last updated February 24, 2025)
HTML sanitizer is written in PHP, aiming to provide XSS-safe markup based on explicitly allowed tags, attributes and values. In versions prior to 1.5.0 or 2.1.1, malicious markup used in a sequence with special HTML CDATA sections cannot be filtered and sanitized due to a parsing issue in the upstream package masterminds/html5. This allows bypassing the cross-site scripting mechanism of typo3/html-sanitizer. The upstream package masterminds/html5 provides HTML raw text elements (`script`, `style`, `noframes`, `noembed` and `iframe`) as DOMText nodes, which were not processed and sanitized further. None of the mentioned elements were defined in the default builder configuration, that's why only custom behaviors, using one of those tag names, were vulnerable to cross-site scripting. This issue has been fixed in versions 1.5.0 and 2.1.1.
0
Attacker Value
Unknown
CVE-2022-33187
Disclosure Date: December 09, 2022 (last updated February 24, 2025)
Brocade SANnav before v2.2.1 logs usernames and encoded passwords in
debug-enabled logs. The vulnerability could allow an attacker with admin
privilege to read sensitive information.
0
Attacker Value
Unknown
CVE-2022-44393
Disclosure Date: December 07, 2022 (last updated February 24, 2025)
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=services/view_service&id=.
0
Attacker Value
Unknown
CVE-2022-30305
Disclosure Date: December 06, 2022 (last updated February 24, 2025)
An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1.5 and FortiDeceptor versions 4.2.0, 4.1.0 through 4.1.1, 4.0.0 through 4.0.2, 3.3.0 through 3.3.3, 3.2.0 through 3.2.2,3.1.0 through 3.1.1 and 3.0.0 through 3.0.2 may allow a remote attacker to repeatedly enter incorrect credentials without causing a log entry, and with no limit on the number of failed authentication attempts.
0
Attacker Value
Unknown
CVE-2022-44348
Disclosure Date: December 02, 2022 (last updated February 24, 2025)
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/orders/update_status.php?id=.
0
Attacker Value
Unknown
CVE-2022-44347
Disclosure Date: December 02, 2022 (last updated February 24, 2025)
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=inquiries/view_inquiry&id=.
0
Attacker Value
Unknown
CVE-2022-44345
Disclosure Date: December 02, 2022 (last updated February 24, 2025)
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=quotes/view_quote&id=.
0
Attacker Value
Unknown
CVE-2022-44277
Disclosure Date: December 02, 2022 (last updated February 24, 2025)
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/classes/Master.php?f=delete_product.
0