Show filters
37 Total Results
Displaying 21-30 of 37
Sort by:
Attacker Value
Unknown
CVE-2022-24465
Disclosure Date: March 09, 2022 (last updated November 29, 2024)
Microsoft Intune Portal for iOS Security Feature Bypass Vulnerability
0
Attacker Value
Unknown
CVE-2020-10257
Disclosure Date: March 10, 2020 (last updated February 21, 2025)
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
0
Attacker Value
Unknown
CVE-2018-19924
Disclosure Date: December 06, 2018 (last updated November 27, 2024)
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. An email address can be modified in between the request for a validation code and the entry of the validation code, leading to storage of an XSS payload contained in the modified address.
0
Attacker Value
Unknown
CVE-2018-19923
Disclosure Date: December 06, 2018 (last updated November 27, 2024)
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is member/member_email.php?action=edit CSRF.
0
Attacker Value
Unknown
CVE-2018-19925
Disclosure Date: December 06, 2018 (last updated November 27, 2024)
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. It has SQL injection via the member/member_order.php type parameter, related to the O_state parameter.
0
Attacker Value
Unknown
CVE-2018-19654
Disclosure Date: November 29, 2018 (last updated November 27, 2024)
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is a discrepancy in username checking between a component that does string validation, and a component that is supposed to query a MySQL database. Thus, it is possible to register a new account with a duplicate username, as demonstrated by use of the test%c2 string when a test account already exists.
0
Attacker Value
Unknown
CVE-2018-14960
Disclosure Date: August 06, 2018 (last updated November 27, 2024)
Xiao5uCompany 1.7 has CSRF via admin/Admin.asp.
0
Attacker Value
Unknown
CVE-2018-14527
Disclosure Date: July 23, 2018 (last updated November 27, 2024)
Feedback.asp in Xiao5uCompany 1.7 has XSS because the XSS protection mechanism in Safe.asp is insufficient (for example, it considers SCRIPT and IMG elements, but does not consider VIDEO elements).
0
Attacker Value
Unknown
CVE-2018-14441
Disclosure Date: July 20, 2018 (last updated November 27, 2024)
An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. admin/admin/fileUploadAction_fileUpload.action allows arbitrary file upload, as demonstrated by a .jsp file with the image/jpeg content type.
0
Attacker Value
Unknown
CVE-2018-14440
Disclosure Date: July 20, 2018 (last updated November 27, 2024)
An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. SQL injection exists via the admin/noticeManageAction_queryNotice.action noticeInfo parameter.
0