Show filters
59 Total Results
Displaying 21-30 of 59
Sort by:
Attacker Value
Unknown
CVE-2022-34956
Disclosure Date: August 02, 2022 (last updated February 24, 2025)
Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_data_for_groups.php.
0
Attacker Value
Unknown
CVE-2022-34955
Disclosure Date: August 02, 2022 (last updated February 24, 2025)
Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_data_for_topusers.php.
0
Attacker Value
Unknown
CVE-2022-35406
Disclosure Date: July 08, 2022 (last updated February 24, 2025)
A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or Intruder, it may be incorrectly interpreted as a redirect.
0
Attacker Value
Unknown
CVE-2021-44230
Disclosure Date: November 30, 2021 (last updated February 23, 2025)
PortSwigger Burp Suite Enterprise Edition before 2021.11 on Windows has weak file permissions for the embedded H2 database, which might lead to privilege escalation. This issue can be exploited by an adversary who has already compromised a valid Windows account on the server via separate means. In this scenario, the compromised account may have inherited read access to sensitive configuration, database, and log files.
0
Attacker Value
Unknown
CVE-2021-29416
Disclosure Date: March 29, 2021 (last updated February 22, 2025)
An issue was discovered in PortSwigger Burp Suite before 2021.2. During viewing of a malicious request, it can be manipulated into issuing a request that does not respect its upstream proxy configuration. This could leak NetNTLM hashes on Windows systems that fail to block outbound SMB.
0
Attacker Value
Unknown
CVE-2020-25287
Disclosure Date: September 13, 2020 (last updated February 22, 2025)
Pligg 2.0.3 allows remote authenticated users to execute arbitrary commands because the template editor can edit any file, as demonstrated by an admin/admin_editor.php the_file=..%2Findex.php&open=Open request.
0
Attacker Value
Unknown
CVE-2018-1153
Disclosure Date: June 18, 2018 (last updated November 26, 2024)
Burp Suite Community Edition 1.7.32 and 1.7.33 fail to validate the server certificate in a couple of HTTPS requests which allows a man in the middle to modify or view traffic.
0
Attacker Value
Unknown
CVE-2018-10377
Disclosure Date: June 17, 2018 (last updated November 26, 2024)
PortSwigger Burp Suite before 1.7.34 has Improper Certificate Validation of the Collaborator server certificate, which might allow man-in-the-middle attackers to obtain interaction data.
0
Attacker Value
Unknown
CVE-2015-6655
Disclosure Date: August 31, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in Pligg CMS 2.0.2 allows remote attackers to hijack the authentication of administrators for requests that add an administrator via a request to admin/admin_users.php.
0
Attacker Value
Unknown
CVE-2014-9096
Disclosure Date: November 26, 2014 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in recover.php in Pligg CMS 2.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) n parameter.
0