Show filters
222 Total Results
Displaying 181-190 of 222
Sort by:
Attacker Value
Unknown

CVE-2014-5016

Disclosure Date: July 21, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in LimeSurvey 2.05+ Build 140618 allow remote attackers to inject arbitrary web script or HTML via (1) the pid attribute to the getAttribute_json function to application/controllers/admin/participantsaction.php in CPDB, (2) the sa parameter to application/views/admin/globalSettings_view.php, or (3) a crafted CSV file to the "Import CSV" functionality.
0
Attacker Value
Unknown

CVE-2014-5018

Disclosure Date: July 21, 2014 (last updated October 05, 2023)
Incomplete blacklist vulnerability in the autoEscape function in common_helper.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to conduct cross-site scripting (XSS) attacks via the GBK charset in the loadname parameter to index.php, related to the survey resume.
0
Attacker Value
Unknown

CVE-2014-5017

Disclosure Date: July 21, 2014 (last updated October 05, 2023)
SQL injection vulnerability in CPDB in application/controllers/admin/participantsaction.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to execute arbitrary SQL commands via the sidx parameter in a JSON request to admin/participants/sa/getParticipants_json, related to a search parameter.
0
Attacker Value
Unknown

CVE-2011-5256

Disclosure Date: February 12, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the tooltips in LimeSurvey before 1.91+ Build 11379-20111116, when viewing survey results, allows remote attackers to inject arbitrary web script or HTML via unknown parameters.
0
Attacker Value
Unknown

CVE-2012-4995

Disclosure Date: September 19, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in admin/userrighthandling.php in LimeSurvey before 1.91+ Build 120224 allows remote attackers to inject arbitrary web script or HTML via the full_name parameter in a moduser action to admin/admin.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2012-4994

Disclosure Date: September 19, 2012 (last updated October 05, 2023)
SQL injection vulnerability in admin/admin.php in LimeSurvey before 1.91+ Build 120224 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a browse action. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2012-4927

Disclosure Date: September 15, 2012 (last updated October 05, 2023)
SQL injection vulnerability in Limesurvey (a.k.a PHPSurveyor) before 1.91+ Build 120224 and earlier allows remote attackers to execute arbitrary SQL commands via the fieldnames parameter to index.php.
0
Attacker Value
Unknown

CVE-2010-5045

Disclosure Date: November 02, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in poll/default.asp in Smart ASP Survey allows remote attackers to inject arbitrary web script or HTML via the catid parameter.
0
Attacker Value
Unknown

CVE-2011-3752

Disclosure Date: September 23, 2011 (last updated October 04, 2023)
LimeSurvey 1.90+ build9642-20101214 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/statistics.php and certain other files.
0
Attacker Value
Unknown

CVE-2011-2386

Disclosure Date: June 08, 2011 (last updated October 04, 2023)
VisiWaveReport.exe in AZO Technologies, Inc. VisiWave Site Survey before 2.1.9 allows user-assisted remote attackers to execute arbitrary code via a (1) vws and (2) vwr file with an invalid Type property, which triggers an untrusted pointer dereference.
0