Show filters
37 Total Results
Displaying 21-30 of 37
Sort by:
Attacker Value
Unknown

CVE-2022-24465

Disclosure Date: March 09, 2022 (last updated November 29, 2024)
Microsoft Intune Portal for iOS Security Feature Bypass Vulnerability
0
Attacker Value
Unknown

CVE-2020-10257

Disclosure Date: March 10, 2020 (last updated February 21, 2025)
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
Attacker Value
Unknown

CVE-2018-19924

Disclosure Date: December 06, 2018 (last updated November 27, 2024)
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. An email address can be modified in between the request for a validation code and the entry of the validation code, leading to storage of an XSS payload contained in the modified address.
0
Attacker Value
Unknown

CVE-2018-19923

Disclosure Date: December 06, 2018 (last updated November 27, 2024)
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is member/member_email.php?action=edit CSRF.
0
Attacker Value
Unknown

CVE-2018-19925

Disclosure Date: December 06, 2018 (last updated November 27, 2024)
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. It has SQL injection via the member/member_order.php type parameter, related to the O_state parameter.
0
Attacker Value
Unknown

CVE-2018-19654

Disclosure Date: November 29, 2018 (last updated November 27, 2024)
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is a discrepancy in username checking between a component that does string validation, and a component that is supposed to query a MySQL database. Thus, it is possible to register a new account with a duplicate username, as demonstrated by use of the test%c2 string when a test account already exists.
Attacker Value
Unknown

CVE-2018-14960

Disclosure Date: August 06, 2018 (last updated November 27, 2024)
Xiao5uCompany 1.7 has CSRF via admin/Admin.asp.
0
Attacker Value
Unknown

CVE-2018-14527

Disclosure Date: July 23, 2018 (last updated November 27, 2024)
Feedback.asp in Xiao5uCompany 1.7 has XSS because the XSS protection mechanism in Safe.asp is insufficient (for example, it considers SCRIPT and IMG elements, but does not consider VIDEO elements).
0
Attacker Value
Unknown

CVE-2018-14441

Disclosure Date: July 20, 2018 (last updated November 27, 2024)
An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. admin/admin/fileUploadAction_fileUpload.action allows arbitrary file upload, as demonstrated by a .jsp file with the image/jpeg content type.
0
Attacker Value
Unknown

CVE-2018-14440

Disclosure Date: July 20, 2018 (last updated November 27, 2024)
An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. SQL injection exists via the admin/noticeManageAction_queryNotice.action noticeInfo parameter.
0