Show filters
39 Total Results
Displaying 21-30 of 39
Sort by:
Attacker Value
Unknown
CVE-2014-5706
Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The SomNote - Journal/Memo (aka com.somcloud.somnote) application 2.1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2011-5196
Disclosure Date: September 23, 2012 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Journal Systems 2.3.6 and earlier allows remote attackers to hijack the authentication of administrators for requests that upload PHP files.
0
Attacker Value
Unknown
CVE-2012-1467
Disclosure Date: September 06, 2012 (last updated October 05, 2023)
Multiple directory traversal vulnerabilities in the iBrowser plugin library, as used in Open Journal Systems before 2.3.7, allow remote authenticated users to (1) delete or (2) rename arbitrary files via a .. (dot dot) in the param parameter to lib/pkp/lib/tinymce/jscripts/tiny_mce/plugins/ibrowser/scripts/rfiles.php.
0
Attacker Value
Unknown
CVE-2012-1468
Disclosure Date: September 06, 2012 (last updated October 05, 2023)
Incomplete blacklist vulnerability in Open Journal Systems before 2.3.7 allows remote authenticated users with the Author Role permission to execute arbitrary code by uploading a file with an executable extension that is not ".php", then accessing it via a direct request to the file in submission/original/ in the associated article directory, as demonstrated using .pHp, .asp, and other extensions.
0
Attacker Value
Unknown
CVE-2012-1469
Disclosure Date: September 06, 2012 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Open Journal Systems before 2.3.7 allow remote attackers and remote authenticated users to inject arbitrary web script or HTML via the (1) editor or (2) callback parameters to lib/pkp/lib/tinymce/jscripts/tiny_mce/plugins/ibrowser/ibrowser.php in the iBrowser plugin, (3) authors[][url] parameter to index.php, or (4) Bio Statement or (5) Abstract of Submission fields to the stripUnsafeHtml function in lib/pkp/classes/core/String.inc.php.
0
Attacker Value
Unknown
CVE-2008-0435
Disclosure Date: January 23, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in OZJournals 2.1.1 allows remote attackers to read portions of arbitrary files via a .. (dot dot) in the id parameter in a printpreview action.
0
Attacker Value
Unknown
CVE-2007-5056
Disclosure Date: September 24, 2007 (last updated October 04, 2023)
Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including CMS Made Simple, SAPID CMF, Journalness, PacerCMS, and Open-Realty, allows remote attackers to execute arbitrary code via PHP sequences in the last_module parameter.
0
Attacker Value
Unknown
CVE-2007-2492
Disclosure Date: May 04, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the v4bJournal module for PostNuke allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a journal_comment action.
0
Attacker Value
Unknown
CVE-2006-5306
Disclosure Date: October 17, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in the Journals System module 1.0.2 (RC2) and earlier for phpBB allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) includes/journals_delete.php, (2) includes/journals_post.php, or (3) includes/journals_edit.php.
0
Attacker Value
Unknown
CVE-2006-4086
Disclosure Date: August 11, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in Elaine Aquino Online Zone Journals (OZJournals) 1.5 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
0