Show filters
733 Total Results
Displaying 251-260 of 733
Sort by:
Attacker Value
Unknown
CVE-2021-21363
Disclosure Date: March 11, 2021 (last updated February 22, 2025)
swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in different languages by parsing your OpenAPI / Swagger definition. In swagger-codegen before version 2.4.19, on Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared temporary directory and race to complete the creation of the temporary subdirectory. This vulnerability is local privilege escalation because the contents of the `outputFolder` can be appended to by an attacker. As such, code written to this directory, when executed can be attacker controlled. For more details refer to the referenced GitHub Security Advisory. This vulnerability is fixed in version 2.4.19. Note this is a distinct vulnerability from CVE-2021-21364.
0
Attacker Value
Unknown
CVE-2021-27568
Disclosure Date: February 23, 2021 (last updated February 22, 2025)
An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information.
0
Attacker Value
Unknown
CVE-2021-26119
Disclosure Date: February 22, 2021 (last updated November 28, 2024)
Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode.
0
Attacker Value
Unknown
CVE-2021-26120
Disclosure Date: February 22, 2021 (last updated February 22, 2025)
Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.
0
Attacker Value
Unknown
CVE-2020-27997
Disclosure Date: February 19, 2021 (last updated February 22, 2025)
An issue was discovered in SmartStoreNET before 4.1.0. Lack of Cross Site Request Forgery (CSRF) protection may lead to elevation of privileges (e.g., /admin/customer/create to create an admin account).
0
Attacker Value
Unknown
CVE-2020-35775
Disclosure Date: February 15, 2021 (last updated February 22, 2025)
CITSmart before 9.1.2.23 allows LDAP Injection.
0
Attacker Value
Unknown
CVE-2021-26551
Disclosure Date: February 09, 2021 (last updated February 22, 2025)
An issue was discovered in SmartFoxServer 2.17.0. An attacker can execute arbitrary Python code, and bypass the javashell.py protection mechanism, by creating /config/ConsoleModuleUnlock.txt and editing /config/admin/admintool.xml to enable the Console module.
0
Attacker Value
Unknown
CVE-2021-26549
Disclosure Date: February 09, 2021 (last updated February 22, 2025)
An XSS issue was discovered in SmartFoxServer 2.17.0. Input passed to the AdminTool console is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML code in a user's browser session in context of an affected site.
0
Attacker Value
Unknown
CVE-2021-26550
Disclosure Date: February 09, 2021 (last updated February 22, 2025)
An issue was discovered in SmartFoxServer 2.17.0. Cleartext password disclosure can occur via /config/server.xml.
0
Attacker Value
Unknown
CVE-2020-26118
Disclosure Date: January 11, 2021 (last updated February 22, 2025)
In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deserialization vulnerability. The application's UpdateMemento class accepts a serialized Java object directly from the user without properly sanitizing it. A malicious object can be submitted to the server via an authenticated attacker to execute commands on the underlying system.
0