Show filters
744 Total Results
Displaying 181-190 of 744
Sort by:
Attacker Value
Unknown

CVE-2023-3573

Disclosure Date: August 08, 2023 (last updated February 25, 2025)
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a command injection in a HTTP POST request releated to font configuration operations to gain full access to the device.
Attacker Value
Unknown

CVE-2023-3572

Disclosure Date: August 08, 2023 (last updated February 25, 2025)
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote, unauthenticated attacker may use an attribute of a specific HTTP POST request releated to date/time operations to gain full access to the device.
Attacker Value
Unknown

CVE-2023-3571

Disclosure Date: August 08, 2023 (last updated February 25, 2025)
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a specific HTTP POST releated to certificate operations to gain full access to the device.
Attacker Value
Unknown

CVE-2023-3570

Disclosure Date: August 08, 2023 (last updated February 25, 2025)
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a specific HTTP DELETE request to gain full access to the device.
Attacker Value
Unknown

CVE-2023-3569

Disclosure Date: August 08, 2023 (last updated February 25, 2025)
In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an authenticated remote attacker with admin privileges could upload a crafted XML file which causes a denial-of-service.
Attacker Value
Unknown

CVE-2023-3526

Disclosure Date: August 08, 2023 (last updated February 25, 2025)
In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an unauthenticated remote attacker could use a reflective XSS within the license viewer page of the devices in order to execute code in the context of the user's browser.
Attacker Value
Unknown

CVE-2023-36806

Disclosure Date: July 25, 2023 (last updated February 25, 2025)
Contao is an open source content management system. Starting in version 4.0.0 and prior to versions 4.9.42, 4.13.28, and 5.1.10, it is possible for untrusted backend users to inject malicious code into headline fields in the back end, which will be executed both in the element preview (back end) and on the website (front end). Installations are only affected if there are untrusted back end users who have the rights to modify headline fields, or other fields using the input unit widget. Contao 4.9.42, 4.13.28, and 5.1.10 have a patch for this issue. As a workaround, disable the login for all untrusted back end users.
Attacker Value
Unknown

CVE-2023-3806

Disclosure Date: July 21, 2023 (last updated February 25, 2025)
A vulnerability, which was classified as critical, was found in SourceCodester House Rental and Property Listing System 1.0. Affected is an unknown function of the file btn_functions.php. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-235074 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-3694

Disclosure Date: July 17, 2023 (last updated February 25, 2025)
A vulnerability, which was classified as critical, has been found in SourceCodester House Rental and Property Listing 1.0. This issue affects some unknown processing of the file index.php. The manipulation of the argument keywords/location leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-234245 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-22694

Disclosure Date: July 10, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Arian Khosravi, Norik Davtian BigContact Contact Page plugin <= 1.5.8 versions.