Show filters
35 Total Results
Displaying 21-30 of 35
Sort by:
Attacker Value
Unknown
CVE-2022-26633
Disclosure Date: May 20, 2022 (last updated February 23, 2025)
Simple Student Quarterly Result/Grade System v1.0 was discovered to contain a SQL injection vulnerability via /sqgs/Actions.php.
0
Attacker Value
Unknown
CVE-2022-1001
Disclosure Date: April 18, 2022 (last updated February 23, 2025)
The WP Downgrade WordPress plugin before 1.2.3 only perform client side validation of its "WordPress Target Version" settings, but does not sanitise and escape it server side, allowing high privilege users such as admin to perform Cross-Site attacks even when the unfiltered_html capability is disallowed
0
Attacker Value
Unknown
CVE-2019-15304
Disclosure Date: August 26, 2019 (last updated November 27, 2024)
Lierda Grill Temperature Monitor V1.00_50006 has a default password of admin for the admin account, which allows an attacker to cause a Denial of Service or Information Disclosure via the undocumented access-point configuration page located on the device. This wifi thermometer app requests and requires excessive permissions to operate such as Fine GPS location, camera, applists, Serial number, IMEI. In addition to the "backdoor" login access for "admin" purposes, this accompanying app also establishes connections with several china based URLs to include Alibaba cloud computing. NOTE: this device also ships with ProGrade branding.
0
Attacker Value
Unknown
CVE-2016-5807
Disclosure Date: July 15, 2016 (last updated November 25, 2024)
Tollgrade LightHouse SMS before 5.1 patch 3 allows remote authenticated users to bypass an intended administrative-authentication requirement, and read or change parameter values, via a direct request.
0
Attacker Value
Unknown
CVE-2016-5797
Disclosure Date: July 15, 2016 (last updated November 25, 2024)
Tollgrade LightHouse SMS before 5.1 patch 3 provides different error messages for failed authentication attempts depending on whether the username exists, which allows remote attackers to enumerate account names via a series of attempts.
0
Attacker Value
Unknown
CVE-2016-0864
Disclosure Date: February 13, 2016 (last updated November 25, 2024)
Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to obtain sensitive report and username information via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-0863
Disclosure Date: February 13, 2016 (last updated November 25, 2024)
Cross-site request forgery (CSRF) vulnerability in Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to hijack the authentication of arbitrary users.
0
Attacker Value
Unknown
CVE-2016-0865
Disclosure Date: February 13, 2016 (last updated November 25, 2024)
Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote authenticated users to change arbitrary passwords via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-0866
Disclosure Date: February 13, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-1670
Disclosure Date: March 31, 2012 (last updated October 04, 2023)
admin/index.php in PHP Grade Book before 1.9.5 BETA allows remote attackers to read the database via a SaveSQL action.
0