Show filters
48 Total Results
Displaying 21-30 of 48
Sort by:
Attacker Value
Unknown

CVE-2021-24558

Disclosure Date: August 23, 2021 (last updated February 23, 2025)
The pspin_duplicate_post_save_as_new_post function of the Project Status WordPress plugin through 1.6 does not sanitise, validate or escape the post GET parameter passed to it before outputting it in an error message when the related post does not exist, leading to a reflected XSS issue
Attacker Value
Unknown

CVE-2021-27222

Disclosure Date: March 08, 2021 (last updated February 22, 2025)
In the "Time in Status" app before 4.13.0 for Jira, remote authenticated attackers can cause Stored XSS.
Attacker Value
Unknown

CVE-2020-5674

Disclosure Date: November 24, 2020 (last updated February 22, 2025)
Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Attacker Value
Unknown

CVE-2014-5091

Disclosure Date: February 07, 2020 (last updated February 21, 2025)
A vulnerability exits in Status2K 2.5 Server Monitoring Software via the multies parameter to includes/functions.php, which could let a malicious user execute arbitrary PHP code.
Attacker Value
Unknown

CVE-2010-4658

Disclosure Date: February 07, 2020 (last updated February 21, 2025)
statusnet through 2010 allows attackers to spoof syslog messages via newline injection attacks.
Attacker Value
Unknown

CVE-2014-5093

Disclosure Date: January 10, 2020 (last updated February 21, 2025)
Status2k does not remove the install directory allowing credential reset.
Attacker Value
Unknown

CVE-2014-5092

Disclosure Date: January 10, 2020 (last updated February 21, 2025)
Status2k allows Remote Command Execution in admin/options/editpl.php.
Attacker Value
Unknown

CVE-2010-4659

Disclosure Date: November 20, 2019 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in statusnet through 2010 in error message contents.
Attacker Value
Unknown

CVE-2010-4660

Disclosure Date: November 20, 2019 (last updated November 27, 2024)
Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes..
Attacker Value
Unknown

CVE-2011-3370

Disclosure Date: November 12, 2019 (last updated November 27, 2024)
statusnet before 0.9.9 has XSS