Show filters
699 Total Results
Displaying 201-210 of 699
Sort by:
Attacker Value
Unknown
CVE-2022-28508
Disclosure Date: May 04, 2022 (last updated February 23, 2025)
An XSS issue was discovered in browser_search_plugin.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input field.
0
Attacker Value
Unknown
CVE-2022-0656
Disclosure Date: April 25, 2022 (last updated February 23, 2025)
The Web To Print Shop : uDraw WordPress plugin before 3.3.3 does not validate the url parameter in its udraw_convert_url_to_base64 AJAX action (available to both unauthenticated and authenticated users) before using it in the file_get_contents function and returning its content base64 encoded in the response. As a result, unauthenticated users could read arbitrary files on the web server (such as /etc/passwd, wp-config.php etc)
0
Attacker Value
Unknown
CVE-2021-43481
Disclosure Date: April 20, 2022 (last updated February 23, 2025)
An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php.
0
Attacker Value
Unknown
CVE-2021-43257
Disclosure Date: April 14, 2022 (last updated February 23, 2025)
Lack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an unprivileged attacker to execute code or gain access to information when a user opens the csv_export.php generated CSV file in Excel.
0
Attacker Value
Unknown
CVE-2022-26144
Disclosure Date: April 13, 2022 (last updated February 23, 2025)
An XSS issue was discovered in MantisBT before 2.25.3. Improper escaping of a Plugin name allows execution of arbitrary code (if CSP allows it) in manage_plugin_page.php and manage_plugin_uninstall.php when a crafted plugin is installed.
0
Attacker Value
Unknown
CVE-2022-1007
Disclosure Date: April 11, 2022 (last updated February 23, 2025)
The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the room parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue
0
Attacker Value
Unknown
CVE-2022-1006
Disclosure Date: April 11, 2022 (last updated February 23, 2025)
The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the id parameter when editing Calendars, which could allow high privilege users such as admin to perform SQL injection attacks
0
Attacker Value
Unknown
CVE-2022-1210
Disclosure Date: April 03, 2022 (last updated February 23, 2025)
A vulnerability classified as problematic was found in LibTIFF 4.3.0. Affected by this vulnerability is the TIFF File Handler of tiff2ps. Opening a malicious file leads to a denial of service. The attack can be launched remotely but requires user interaction. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2022-1056
Disclosure Date: March 28, 2022 (last updated February 23, 2025)
Out-of-bounds Read error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 46dc8fcd.
0
Attacker Value
Unknown
CVE-2022-0694
Disclosure Date: March 21, 2022 (last updated February 23, 2025)
The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injection
0