Show filters
664 Total Results
Displaying 201-210 of 664
Sort by:
Attacker Value
Unknown

CVE-2018-11688

Disclosure Date: June 13, 2018 (last updated November 26, 2024)
Ignite Realtime Openfire before 3.9.2 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
0
Attacker Value
Unknown

CVE-2017-2815

Disclosure Date: May 15, 2018 (last updated November 26, 2024)
An exploitable XML entity injection vulnerability exists in OpenFire User Import Export Plugin 2.6.0. A specially crafted web request can cause the retrieval of arbitrary files or denial of service. An authenticated attacker can send a crafted web request to trigger this vulnerability.
0
Attacker Value
Unknown

CVE-2018-7319

Disclosure Date: February 22, 2018 (last updated November 26, 2024)
SQL Injection exists in the OS Property Real Estate 3.12.7 component for Joomla! via the cooling_system1, heating_system1, or laundry parameter.
0
Attacker Value
Unknown

CVE-2018-6005

Disclosure Date: February 17, 2018 (last updated November 26, 2024)
SQL Injection exists in the Realpin through 1.5.04 component for Joomla! via the pinboard parameter.
0
Attacker Value
Unknown

CVE-2018-6796

Disclosure Date: February 07, 2018 (last updated November 26, 2024)
PHP Scripts Mall Multilanguage Real Estate MLM Script 3.0 has Stored XSS via every profile input field.
0
Attacker Value
Unknown

CVE-2018-6364

Disclosure Date: January 29, 2018 (last updated November 26, 2024)
SQL Injection exists in Multilanguage Real Estate MLM Script through 3.0 via the /product-list.php srch parameter.
0
Attacker Value
Unknown

CVE-2018-5075

Disclosure Date: January 03, 2018 (last updated November 26, 2024)
Online Ticket Booking has XSS via the admin/snacks_edit.php snacks_name parameter.
0
Attacker Value
Unknown

CVE-2018-5073

Disclosure Date: January 03, 2018 (last updated November 26, 2024)
Online Ticket Booking has CSRF via admin/movieedit.php.
0
Attacker Value
Unknown

CVE-2018-5076

Disclosure Date: January 03, 2018 (last updated November 26, 2024)
Online Ticket Booking has XSS via the admin/newsedit.php newstitle parameter.
0
Attacker Value
Unknown

CVE-2018-5072

Disclosure Date: January 03, 2018 (last updated November 26, 2024)
Online Ticket Booking has XSS via the admin/sitesettings.php keyword parameter.
0