Show filters
596 Total Results
Displaying 201-210 of 596
Sort by:
Attacker Value
Unknown

CVE-2020-24699

Disclosure Date: August 31, 2020 (last updated February 22, 2025)
The Chamber Dashboard Business Directory plugin 3.2.8 for WordPress allows XSS.
Attacker Value
Unknown

CVE-2020-14565

Disclosure Date: July 15, 2020 (last updated November 28, 2024)
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Unified Directory. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Unified Directory accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Unified Directory. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H).
Attacker Value
Unknown

CVE-2019-13463

Disclosure Date: March 20, 2020 (last updated February 21, 2025)
An XSS vulnerability in qcopd-shortcode-generator.php in the Simple Link Directory plugin before 7.3.5 for WordPress allows remote attackers to inject arbitrary web script or HTML, because esc_html is not called for the "echo get_the_title()" or "echo $term->name" statement.
Attacker Value
Unknown

CVE-2020-5182

Disclosure Date: February 03, 2020 (last updated February 21, 2025)
The J-BusinessDirectory extension before 5.2.9 for Joomla! allows Reverse Tabnabbing. In some configurations, the link to the business website can be entered by any user. If it doesn't contain rel="noopener" (or similar attributes such as noreferrer), the tabnabbing may occur. To reproduce the bug, create a business with a website link that contains JavaScript to exploit the window.opener property (for example, by setting window.opener.location).
Attacker Value
Unknown

CVE-2019-4551

Disclosure Date: February 03, 2020 (last updated February 21, 2025)
IBM Security Directory Server 6.4.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 165953.
Attacker Value
Unknown

CVE-2019-4548

Disclosure Date: February 03, 2020 (last updated February 21, 2025)
IBM Security Directory Server 6.4.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 165950.
Attacker Value
Unknown

CVE-2019-4562

Disclosure Date: February 03, 2020 (last updated February 21, 2025)
IBM Security Directory Server 6.4.0 stores sensitive information in URLs. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer header or browser history. IBM X-Force ID: 166623.
Attacker Value
Unknown

CVE-2019-4541

Disclosure Date: February 03, 2020 (last updated November 27, 2024)
IBM Security Directory Server 6.4.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 165814.
Attacker Value
Unknown

CVE-2019-4540

Disclosure Date: February 03, 2020 (last updated February 21, 2025)
IBM Security Directory Server 6.4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 165813.
Attacker Value
Unknown

CVE-2019-4550

Disclosure Date: February 03, 2020 (last updated November 27, 2024)
IBM Security Directory Server 6.4.0 is deployed with active debugging code that can create unintended entry points. IBM X-Force ID: 165952.