Show filters
664 Total Results
Displaying 231-240 of 664
Sort by:
Attacker Value
Unknown
CVE-2015-6972
Disclosure Date: September 16, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to inject arbitrary web script or HTML via the (1) groupchatName parameter to plugins/clientcontrol/create-bookmark.jsp; the (2) urlName parameter to plugins/clientcontrol/create-bookmark.jsp; the (3) hostname parameter to server-session-details.jsp; or the (4) search parameter to group-summary.jsp.
0
Attacker Value
Unknown
CVE-2015-6973
Disclosure Date: September 16, 2015 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to hijack the authentication of administrators for requests that (1) change a password via a crafted request to user-password.jsp, (2) add users via a crafted request to user-create.jsp, (3) edit server settings or (4) disable SSL on the server via a crafted request to server-props.jsp, or (5) add clients via a crafted request to plugins/clientcontrol/permitted-clients.jsp.
0
Attacker Value
Unknown
CVE-2015-5506
Disclosure Date: August 18, 2015 (last updated October 05, 2023)
The Apache Solr Real-Time module 7.x-1.x before 7.x-1.2 for Drupal does not check the status of an entity when indexing, which allows remote attackers to obtain information about unpublished content via a search.
0
Attacker Value
Unknown
CVE-2015-2704
Disclosure Date: May 18, 2015 (last updated October 05, 2023)
realmd allows remote attackers to inject arbitrary configurations in to sssd.conf and smb.conf via a newline character in an LDAP response.
0
Attacker Value
Unknown
CVE-2014-8361
Disclosure Date: May 01, 2015 (last updated June 28, 2024)
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.
0
Attacker Value
Unknown
CVE-2013-2604
Disclosure Date: January 12, 2015 (last updated October 05, 2023)
RealNetworks GameHouse RealArcade Installer (aka ActiveMARK Game Installer) 2.6.0.481 and 3.0.7 uses weak permissions (Create Files/Write Data) for the GameHouse Games directory tree, which allows local users to gain privileges via a Trojan horse DLL in an individual game's directory, as demonstrated by DDRAW.DLL in the Zuma Deluxe directory.
0
Attacker Value
Unknown
CVE-2013-2603
Disclosure Date: January 12, 2015 (last updated October 05, 2023)
The RACInstaller.StateCtrl.1 ActiveX control in InstallerDlg.dll in RealNetworks GameHouse RealArcade Installer 2.6.0.481 performs unexpected type conversions for invalid parameter types, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted arguments to the (1) AddTag, (2) Ping, (3) QueuePause, (4) QueueRemove, (5) QueueTop, (6) RemoveTag, (7) TagRemoved, or (8) message method.
0
Attacker Value
Unknown
CVE-2014-9461
Disclosure Date: January 02, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in models/Cart66.php in the Cart66 Lite plugin before 1.5.4 for WordPress allows remote authenticated users to read arbitrary files via a .. (dot dot) in the member_download action to wp-admin/admin-ajax.php.
0
Attacker Value
Unknown
CVE-2014-9442
Disclosure Date: January 02, 2015 (last updated October 05, 2023)
SQL injection vulnerability in models/Cart66Ajax.php in the Cart66 Lite plugin before 1.5.4 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the q parameter in a promotionProductSearch action to wp-admin/admin-ajax.php.
0
Attacker Value
Unknown
CVE-2014-9305
Disclosure Date: December 08, 2014 (last updated October 05, 2023)
SQL injection vulnerability in the shortcodeProductsTable function in models/Cart66Ajax.php in the Cart66 Lite plugin before 1.5.2 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a shortcode_products_table action to wp-admin/admin-ajax.php.
0