Show filters
469 Total Results
Displaying 241-250 of 469
Sort by:
Attacker Value
Unknown

CVE-2018-1000875

Disclosure Date: December 20, 2018 (last updated November 27, 2024)
Berkeley Open Infrastructure for Network Computing BOINC Server and Website Code version 0.9-1.0.2 contains a CWE-302: Authentication Bypass by Assumed-Immutable Data vulnerability in Website Terms of Service Acceptance Page that can result in Access to any user account. This attack appear to be exploitable via Specially crafted URL. This vulnerability appears to have been fixed in 1.0.3.
0
Attacker Value
Unknown

CVE-2018-12076

Disclosure Date: December 13, 2018 (last updated February 15, 2024)
A vulnerability in the UPC bar code of the Avanti Markets MarketCard could allow an unauthenticated, local attacker to access funds within the customer's MarketCard balance, and also could lead to Customer Information Disclosure. The vulnerability is due to lack of proper validation of the UPC bar code present on the MarketCard. An attacker could exploit this vulnerability by generating a copy of a customer's bar code. An exploit could allow the attacker to access all funds located within the MarketCard or allow unauthenticated disclosure of information.
0
Attacker Value
Unknown

CVE-2018-2486

Disclosure Date: December 11, 2018 (last updated November 27, 2024)
SAP Marketing (UICUAN (1.20, 1.30, 1.40), SAPSCORE (1.13, 1.14)) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
0
Attacker Value
Unknown

CVE-2018-1920

Disclosure Date: December 07, 2018 (last updated November 27, 2024)
IBM Marketing Platform 9.1.0, 9.1.2 and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 152855.
0
Attacker Value
Unknown

CVE-2018-1424

Disclosure Date: December 07, 2018 (last updated November 27, 2024)
IBM Marketing Platform 9.1.0, 9.1.2, and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 139029.
0
Attacker Value
Unknown

CVE-2018-19651

Disclosure Date: November 28, 2018 (last updated November 08, 2023)
admin/functions/remote.php in Interspire Email Marketer through 6.1.6 has Server Side Request Forgery (SSRF) via a what=importurl&url= request with an http or https URL. This also allows reading local files with a file: URL.
0
Attacker Value
Unknown

CVE-2018-19552

Disclosure Date: November 26, 2018 (last updated November 08, 2023)
Interspire Email Marketer through 6.1.6 has SQL Injection via a deleteblock blockid[] request to Dynamiccontenttags.php.
0
Attacker Value
Unknown

CVE-2018-19550

Disclosure Date: November 26, 2018 (last updated November 08, 2023)
Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can cause a .php file to be accessible under a admin/temp/surveys/ URI.
0
Attacker Value
Unknown

CVE-2018-19549

Disclosure Date: November 26, 2018 (last updated November 08, 2023)
Interspire Email Marketer through 6.1.6 has SQL Injection via a tagids Delete action to Dynamiccontenttags.php.
0
Attacker Value
Unknown

CVE-2018-19551

Disclosure Date: November 26, 2018 (last updated November 08, 2023)
Interspire Email Marketer through 6.1.6 has SQL Injection via a checkduplicatetags tagname request to Dynamiccontenttags.php.
0