Show filters
568 Total Results
Displaying 251-260 of 568
Sort by:
Attacker Value
Unknown
CVE-2018-7667
Disclosure Date: March 05, 2018 (last updated November 26, 2024)
Adminer through 4.3.1 has SSRF via the server parameter.
0
Attacker Value
Unknown
CVE-2018-7260
Disclosure Date: February 21, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in db_central_columns.php in phpMyAdmin before 4.7.8 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
0
Attacker Value
Unknown
CVE-2018-1000025
Disclosure Date: February 09, 2018 (last updated November 26, 2024)
Jerome Gamez Firebase Admin SDK for PHP version from 3.2.0 to 3.8.0 contains a Incorrect Access Control vulnerability in src/Firebase/Auth/IdTokenVerifier.php does not verify for token signature that can result in JWT with any email address and user ID could be forged from an actual token, or from thin air. This attack appear to be exploitable via Attacker would only need to know email address of the victim on most cases.. This vulnerability appears to have been fixed in 3.8.1.
0
Attacker Value
Unknown
CVE-2017-18045
Disclosure Date: January 21, 2018 (last updated November 26, 2024)
JBMC DirectAdmin before 1.52, when the email_ftp_password_change setting is nonzero, allows remote attackers to obtain access or cause a denial of service (segfault) via an unspecified request.
0
Attacker Value
Unknown
CVE-2017-12098
Disclosure Date: January 19, 2018 (last updated November 26, 2024)
An exploitable cross site scripting (XSS) vulnerability exists in the add filter functionality of the rails_admin rails gem version 1.2.0. A specially crafted URL can cause an XSS flaw resulting in an attacker being able to execute arbitrary javascript on the victim's browser. An attacker can phish an authenticated user to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2017-1000499
Disclosure Date: January 03, 2018 (last updated November 26, 2024)
phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc.
0
Attacker Value
Unknown
CVE-2017-12881
Disclosure Date: August 18, 2017 (last updated November 26, 2024)
Cross-site request forgery (CSRF) vulnerability in the Spring Batch Admin before 1.3.0 allows remote attackers to hijack the authentication of unspecified victims and submit arbitrary requests, such as exploiting the file upload vulnerability.
0
Attacker Value
Unknown
CVE-2017-12882
Disclosure Date: August 18, 2017 (last updated November 26, 2024)
Stored Cross-site scripting (XSS) vulnerability in Spring Batch Admin before 1.3.0 allows remote authenticated users to inject arbitrary JavaScript or HTML via the file upload functionality.
0
Attacker Value
Unknown
CVE-2017-1000016
Disclosure Date: July 17, 2017 (last updated November 26, 2024)
A weakness was discovered where an attacker can inject arbitrary values in to the browser cookies. This is a re-issue of an incomplete fix from PMASA-2016-18.
0
Attacker Value
Unknown
CVE-2017-1000018
Disclosure Date: July 17, 2017 (last updated November 26, 2024)
phpMyAdmin 4.0, 4.4., and 4.6 are vulnerable to a DOS attack in the replication status by using a specially crafted table name
0