Show filters
81 Total Results
Displaying 21-30 of 81
Sort by:
Attacker Value
Unknown

CVE-2023-33207

Disclosure Date: November 13, 2023 (last updated November 17, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Krzysztof Wielogórski Stop Referrer Spam plugin <= 1.3.0 versions.
Attacker Value
Unknown

CVE-2023-4284

Disclosure Date: September 04, 2023 (last updated October 08, 2023)
The Post Timeline WordPress plugin before 2.2.6 does not sanitise and escape an invalid nonce before outputting it back in an AJAX response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Attacker Value
Unknown

CVE-2023-4151

Disclosure Date: September 04, 2023 (last updated October 08, 2023)
The Store Locator WordPress plugin before 1.4.13 does not sanitise and escape an invalid nonce before outputting it back in an AJAX response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Attacker Value
Unknown

CVE-2022-48604

Disclosure Date: August 09, 2023 (last updated November 08, 2023)
A SQL injection vulnerability exists in the “logging export” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.
Attacker Value
Unknown

CVE-2022-48603

Disclosure Date: August 09, 2023 (last updated November 08, 2023)
A SQL injection vulnerability exists in the “message viewer iframe” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.
Attacker Value
Unknown

CVE-2022-48602

Disclosure Date: August 09, 2023 (last updated November 08, 2023)
A SQL injection vulnerability exists in the “message viewer print” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.
Attacker Value
Unknown

CVE-2022-48601

Disclosure Date: August 09, 2023 (last updated November 08, 2023)
A SQL injection vulnerability exists in the “network print report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.
Attacker Value
Unknown

CVE-2022-48600

Disclosure Date: August 09, 2023 (last updated November 08, 2023)
A SQL injection vulnerability exists in the “notes view” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.
Attacker Value
Unknown

CVE-2022-48599

Disclosure Date: August 09, 2023 (last updated November 08, 2023)
A SQL injection vulnerability exists in the “reporter events type” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.
Attacker Value
Unknown

CVE-2022-48598

Disclosure Date: August 09, 2023 (last updated November 08, 2023)
A SQL injection vulnerability exists in the “reporter events type date” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.