Show filters
4,018 Total Results
Displaying 231-240 of 4,018
Sort by:
Attacker Value
Unknown

CVE-2023-3465

Disclosure Date: June 29, 2023 (last updated February 25, 2025)
A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file user.php of the component HTTP POST Request Handler. The manipulation of the argument title leads to cross site scripting. The attack can be launched remotely. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-232711.
Attacker Value
Unknown

CVE-2023-3464

Disclosure Date: June 29, 2023 (last updated February 25, 2025)
A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been classified as problematic. Affected is an unknown function of the file /preview.php of the component URL Parameter Handler. The manipulation of the argument p leads to cross site scripting. It is possible to launch the attack remotely. It is recommended to upgrade the affected component. VDB-232710 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-35169

Disclosure Date: June 23, 2023 (last updated February 25, 2025)
PHP-IMAP is a wrapper for common IMAP communication without the need to have the php-imap module installed / enabled. Prior to version 5.3.0, an unsanitized attachment filename allows any unauthenticated user to leverage a directory traversal vulnerability, which results in a remote code execution vulnerability. Every application that stores attachments with `Attachment::save()` without providing a `$filename` or passing unsanitized user input is affected by this attack. An attacker can send an email with a malicious attachment to the inbox, which gets crawled with `webklex/php-imap` or `webklex/laravel-imap`. Prerequisite for the vulnerability is that the script stores the attachments without providing a `$filename`, or providing an unsanitized `$filename`, in `src/Attachment::save(string $path, string $filename = null)`. In this case, where no `$filename` gets passed into the `Attachment::save()` method, the package would use a series of unsanitized and insecure input values from t…
Attacker Value
Unknown

CVE-2020-21486

Disclosure Date: June 20, 2023 (last updated February 25, 2025)
SQL injection vulnerability in PHPOK v.5.4. allows a remote attacker to obtain sensitive information via the _userlist function in framerwork/phpok_call.php file.
Attacker Value
Unknown

CVE-2020-21400

Disclosure Date: June 20, 2023 (last updated February 25, 2025)
SQL injection vulnerability in gaozhifeng PHPMyWind v.5.6 allows a remote attacker to execute arbitrary code via the id variable in the modify function.
Attacker Value
Unknown

CVE-2023-33601

Disclosure Date: June 07, 2023 (last updated February 25, 2025)
An arbitrary file upload vulnerability in /admin.php?c=upload of phpok v6.4.100 allows attackers to execute arbitrary code via a crafted PHP file.
Attacker Value
Unknown

CVE-2023-2999

Disclosure Date: May 31, 2023 (last updated February 25, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.14.
Attacker Value
Unknown

CVE-2023-2998

Disclosure Date: May 31, 2023 (last updated February 25, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.14.
Attacker Value
Unknown

CVE-2023-2888

Disclosure Date: May 25, 2023 (last updated February 25, 2025)
A vulnerability, which was classified as problematic, was found in PHPOK 6.4.100. This affects an unknown part of the file /admin.php?c=upload&f=zip&_noCache=0.1683794968. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The identifier VDB-229953 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-2753

Disclosure Date: May 17, 2023 (last updated February 25, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.0-beta.