Show filters
545 Total Results
Displaying 181-190 of 545
Sort by:
Attacker Value
Unknown

CVE-2021-26550

Disclosure Date: February 09, 2021 (last updated February 22, 2025)
An issue was discovered in SmartFoxServer 2.17.0. Cleartext password disclosure can occur via /config/server.xml.
Attacker Value
Unknown

CVE-2021-22875

Disclosure Date: January 28, 2021 (last updated February 22, 2025)
Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in stats.php via the `setPerPage` parameter.
Attacker Value
Unknown

CVE-2021-22874

Disclosure Date: January 28, 2021 (last updated February 22, 2025)
Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in userlog-index.php via the `period_preset` parameter.
Attacker Value
Unknown

CVE-2021-3317

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of the source parameter.
Attacker Value
Unknown

CVE-2021-22873

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php delivery scripts. Such open redirects had previously been available by design to allow third party ad servers to track such metrics when delivering ads. However, third party click tracking via redirects is not a viable option anymore, leading to such open redirect functionality being removed and reclassified as a vulnerability.
Attacker Value
Unknown

CVE-2021-22871

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
Revive Adserver before 5.1.0 permits any user with a manager account to store possibly malicious content in the URL website property, which is then displayed unsanitized in the affiliate-preview.php tag generation screen, leading to a persistent cross-site scripting (XSS) vulnerability.
Attacker Value
Unknown

CVE-2021-22872

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
Revive Adserver before 5.1.0 is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the publicly accessible afr.php delivery script. While this issue was previously addressed in modern browsers as CVE-2020-8115, some older browsers (e.g., IE10) that do not automatically URL encode parameters were still vulnerable.
Attacker Value
Unknown

CVE-2020-27735

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
An XSS issue was discovered in Wing FTP 6.4.4. An arbitrary IFRAME element can be included in the help pages via a crafted link, leading to the execution of (sandboxed) arbitrary HTML and JavaScript in the user's browser.
Attacker Value
Unknown

CVE-2020-27858

Disclosure Date: January 20, 2021 (last updated February 22, 2025)
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2D 16.5. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getNews method. Due to the improper restriction of XML External Entity (XXE) references, a specially-crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM. Was ZDI-CAN-11103.
Attacker Value
Unknown

CVE-2020-35857

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the trust-dns-server crate before 0.18.1 for Rust. DNS MX and SRV null targets are mishandled, causing stack consumption.