Show filters
30 Total Results
Displaying 21-30 of 30
Sort by:
Attacker Value
Unknown
CVE-2018-12290
Disclosure Date: June 13, 2018 (last updated November 26, 2024)
The Yii2-StateMachine extension v2.x.x for Yii2 has XSS.
0
Attacker Value
Unknown
CVE-2018-7269
Disclosure Date: March 21, 2018 (last updated November 26, 2024)
The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduct SQL injection attacks via a findOne() or findAll() call, unless a developer recognizes an undocumented need to sanitize array input.
0
Attacker Value
Unknown
CVE-2018-8074
Disclosure Date: March 21, 2018 (last updated November 26, 2024)
Yii 2.x before 2.0.15 allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269 attack in conjunction with the Elasticsearch extension.
0
Attacker Value
Unknown
CVE-2018-8073
Disclosure Date: March 21, 2018 (last updated November 26, 2024)
Yii 2.x before 2.0.15 allows remote attackers to execute arbitrary LUA code via a variant of the CVE-2018-7269 attack in conjunction with the Redis extension.
0
Attacker Value
Unknown
CVE-2018-6010
Disclosure Date: January 22, 2018 (last updated November 26, 2024)
In Yii Framework 2.x before 2.0.14, remote attackers could obtain potentially sensitive information from exception messages, or exploit reflected XSS on the error handler page in non-debug mode. Related to base/ErrorHandler.php, log/Dispatcher.php, and views/errorHandler/exception.php.
0
Attacker Value
Unknown
CVE-2018-6009
Disclosure Date: January 22, 2018 (last updated November 26, 2024)
In Yii Framework 2.x before 2.0.14, the switchIdentity function in web/User.php did not regenerate the CSRF token upon a change of identity.
0
Attacker Value
Unknown
CVE-2017-11516
Disclosure Date: July 21, 2017 (last updated November 26, 2024)
An XSS vulnerability exists in framework/views/errorHandler/exception.php in Yii Framework 2.0.12 affecting the exception screen when debug mode is enabled, because $exception->errorInfo is mishandled.
0
Attacker Value
Unknown
CVE-2017-7271
Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Reflected Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.11, when development mode is used, allows remote attackers to inject arbitrary web script or HTML via crafted request data that is mishandled on the debug-mode exception screen.
0
Attacker Value
Unknown
CVE-2015-3397
Disclosure Date: May 14, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via vectors related to JSON, arrays, and Internet Explorer 6 or 7.
0
Attacker Value
Unknown
CVE-2014-4672
Disclosure Date: July 03, 2014 (last updated October 05, 2023)
The CDetailView widget in Yii PHP Framework 1.1.14 allows remote attackers to execute arbitrary PHP scripts via vectors related to the value property.
0