Show filters
664 Total Results
Displaying 211-220 of 664
Sort by:
Attacker Value
Unknown
CVE-2018-5078
Disclosure Date: January 03, 2018 (last updated November 26, 2024)
Online Ticket Booking has XSS via the admin/eventlist.php cast parameter.
0
Attacker Value
Unknown
CVE-2018-5077
Disclosure Date: January 03, 2018 (last updated November 26, 2024)
Online Ticket Booking has XSS via the admin/movieedit.php moviename parameter.
0
Attacker Value
Unknown
CVE-2018-5074
Disclosure Date: January 03, 2018 (last updated November 26, 2024)
Online Ticket Booking has XSS via the admin/manageownerlist.php contact parameter.
0
Attacker Value
Unknown
CVE-2017-17909
Disclosure Date: December 27, 2017 (last updated November 26, 2024)
PHP Scripts Mall Responsive Realestate Script has XSS via the admin/general.php gplus parameter.
0
Attacker Value
Unknown
CVE-2017-17908
Disclosure Date: December 27, 2017 (last updated November 26, 2024)
PHP Scripts Mall Responsive Realestate Script has CSRF via admin/general.
0
Attacker Value
Unknown
CVE-2017-17591
Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Realestate Crowdfunding Script 2.7.2 has SQL Injection via the single-cause.php pid parameter.
0
Attacker Value
Unknown
CVE-2017-17603
Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_price, or maxprice parameter.
0
Attacker Value
Unknown
CVE-2017-17628
Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
0
Attacker Value
Unknown
CVE-2017-3767
Disclosure Date: November 13, 2017 (last updated November 26, 2024)
A local privilege escalation vulnerability was identified in the Realtek audio driver versions prior to 6.0.1.8224 in some Lenovo ThinkPad products. An attacker with local privileges could execute code with administrative privileges.
0
Attacker Value
Unknown
CVE-2017-15911
Disclosure Date: October 26, 2017 (last updated November 26, 2024)
The Admin Console in Ignite Realtime Openfire Server before 4.1.7 allows arbitrary client-side JavaScript code execution on victims who click a crafted setup/setup-host-settings.jsp?domain= link, aka XSS. Session ID and data theft may follow as well as the possibility of bypassing CSRF protections, injection of iframes to establish communication channels, etc. The vulnerability is present after login into the application.
0