Show filters
29 Total Results
Displaying 21-29 of 29
Sort by:
Attacker Value
Unknown

CVE-2014-5981

Disclosure Date: September 20, 2014 (last updated October 05, 2023)
The MoWeather (aka com.moji.moweather) application 1.40.05 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2013-2618

Disclosure Date: June 05, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in editor.php in Network Weathermap before 0.97b allows remote attackers to inject arbitrary web script or HTML via the map_title parameter.
0
Attacker Value
Unknown

CVE-2013-3739

Disclosure Date: June 05, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in editor.php in Network Weathermap 0.97c and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the mapname parameter in a show_config action.
0
Attacker Value
Unknown

CVE-2012-5187

Disclosure Date: February 06, 2013 (last updated October 05, 2023)
The Weathernews Touch application 2.3.2 and earlier for Android allows attackers to obtain sensitive information about logged locations via a crafted application that leverages read permission for system log files.
0
Attacker Value
Unknown

CVE-2008-5770

Disclosure Date: December 30, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in config/make_config.php in PHP Weather 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
0
Attacker Value
Unknown

CVE-2008-5771

Disclosure Date: December 30, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in test.php in PHP Weather 2.2.2 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the language parameter.
0
Attacker Value
Unknown

CVE-2006-5519

Disclosure Date: October 26, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in Savant2/Savant2_Plugin_options.php in the MambWeather 1.8.1 and earlier component for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
0
Attacker Value
Unknown

CVE-2006-5185

Disclosure Date: October 10, 2006 (last updated October 04, 2023)
Eval injection vulnerability in Template.php in HAMweather 3.9.8.4 and earlier allows remote attackers to execute arbitrary code via a modified query string, which is supplied to an eval function call within the do_parse_code function.
0
Attacker Value
Unknown

CVE-2002-2356

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
HAMweather 2.x allows remote attackers to modify administrative settings and obtain sensitive information via a direct request to hwadmin.cgi.
0