Show filters
215 Total Results
Displaying 191-200 of 215
Sort by:
Attacker Value
Unknown
CVE-2016-4567
Disclosure Date: May 22, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by "jsinitfunctio%gn."
0
Attacker Value
Unknown
CVE-2013-4503
Disclosure Date: May 13, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Feed Element Mapper module for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via vectors related to options.
0
Attacker Value
Unknown
CVE-2013-1967
Disclosure Date: February 05, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in flashmediaelement.swf in MediaElement.js before 2.11.2, as used in ownCloud Server 5.0.x before 5.0.5 and 4.5.x before 4.5.10, allows remote attackers to inject arbitrary web script or HTML via the file parameter.
0
Attacker Value
Unknown
CVE-2009-4966
Disclosure Date: July 28, 2010 (last updated October 04, 2023)
SQL injection vulnerability in the AST ZipCodeSearch (ast_addresszipsearch) extension 0.5.4 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2009-4817
Disclosure Date: April 27, 2010 (last updated October 04, 2023)
Unrestricted file upload vulnerability in Element-IT Ultimate Uploader 1.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in upload/.
0
Attacker Value
Unknown
CVE-2006-2715
Disclosure Date: May 31, 2006 (last updated October 04, 2023)
The Administration Console in Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 does not enforce access control, which allows remote attackers to gain access to servers via the console.
0
Attacker Value
Unknown
CVE-2006-2707
Disclosure Date: May 31, 2006 (last updated October 04, 2023)
Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 does not validate the peer certificate when obtaining an update, which could allow remote attackers to distribute malicious updates to clients.
0
Attacker Value
Unknown
CVE-2006-2711
Disclosure Date: May 31, 2006 (last updated October 04, 2023)
Secure Elements Class 5 AVR (aka C5 EVM) 2.8.1 and earlier, and possibly later 2.8.x releases, uses the same initialization vector and key for each message session, which allows remote attackers to obtain potentially sensitive information about messages.
0
Attacker Value
Unknown
CVE-2006-2712
Disclosure Date: May 31, 2006 (last updated October 04, 2023)
Secure Elements Class 5 AVR (aka C5 EVM) client and server before 2.8.1 do not verify the integrity of a message digest, which allows remote attackers to modify and replay messages.
0
Attacker Value
Unknown
CVE-2006-2708
Disclosure Date: May 31, 2006 (last updated October 04, 2023)
Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 allows remote attackers to read portions of process memory via a modified size for (1) EM_GET_CE_PARAMETER and (2) EM_SET_CE_PARAMETER messages, which leads to a buffer overflow (probably an over-read).
0