Show filters
81 Total Results
Displaying 21-30 of 81
Sort by:
Attacker Value
Unknown
CVE-2023-33207
Disclosure Date: November 13, 2023 (last updated November 17, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Krzysztof Wielogórski Stop Referrer Spam plugin <= 1.3.0 versions.
0
Attacker Value
Unknown
CVE-2023-4284
Disclosure Date: September 04, 2023 (last updated October 08, 2023)
The Post Timeline WordPress plugin before 2.2.6 does not sanitise and escape an invalid nonce before outputting it back in an AJAX response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
0
Attacker Value
Unknown
CVE-2023-4151
Disclosure Date: September 04, 2023 (last updated October 08, 2023)
The Store Locator WordPress plugin before 1.4.13 does not sanitise and escape an invalid nonce before outputting it back in an AJAX response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
0
Attacker Value
Unknown
CVE-2022-48604
Disclosure Date: August 09, 2023 (last updated November 08, 2023)
A SQL injection vulnerability exists in the “logging export” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.
0
Attacker Value
Unknown
CVE-2022-48603
Disclosure Date: August 09, 2023 (last updated November 08, 2023)
A SQL injection vulnerability exists in the “message viewer iframe” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.
0
Attacker Value
Unknown
CVE-2022-48602
Disclosure Date: August 09, 2023 (last updated November 08, 2023)
A SQL injection vulnerability exists in the “message viewer print” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.
0
Attacker Value
Unknown
CVE-2022-48601
Disclosure Date: August 09, 2023 (last updated November 08, 2023)
A SQL injection vulnerability exists in the “network print report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.
0
Attacker Value
Unknown
CVE-2022-48600
Disclosure Date: August 09, 2023 (last updated November 08, 2023)
A SQL injection vulnerability exists in the “notes view” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.
0
Attacker Value
Unknown
CVE-2022-48599
Disclosure Date: August 09, 2023 (last updated November 08, 2023)
A SQL injection vulnerability exists in the “reporter events type” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.
0
Attacker Value
Unknown
CVE-2022-48598
Disclosure Date: August 09, 2023 (last updated November 08, 2023)
A SQL injection vulnerability exists in the “reporter events type date” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.
0