Show filters
545 Total Results
Displaying 261-270 of 545
Sort by:
Attacker Value
Unknown

CVE-2019-5440

Disclosure Date: May 28, 2019 (last updated November 27, 2024)
Use of cryptographically weak PRNG in the password recovery token generation of Revive Adserver < v4.2.1 causes a potential authentication bypass attack if an attacker exploits the password recovery functionality. In lib/OA/Dal/PasswordRecovery.php, the function generateRecoveryId() generates a password reset token that relies on the PHP uniqid function and consequently depends only on the current server time, which is often visible in an HTTP Date header.
0
Attacker Value
Unknown

CVE-2019-12250

Disclosure Date: May 21, 2019 (last updated November 08, 2023)
IdentityServer IdentityServer4 through 2.4 has stored XSS via the httpContext to the host/Extensions/RequestLoggerMiddleware.cs LogForErrorContext method, which can be triggered by viewing a log. NOTE: the software maintainer disputes that this is a vulnerability because the request logger is not part of IdentityServer but only our development test host
0
Attacker Value
Unknown

CVE-2019-5433

Disclosure Date: May 06, 2019 (last updated November 27, 2024)
A user having access to the UI of a Revive Adserver instance could be tricked into clicking on a specifically crafted admin account-switch.php URL that would eventually lead them to another (unsafe) domain, potentially used for stealing credentials or other phishing attacks. This vulnerability was addressed in version 4.2.0.
0
Attacker Value
Unknown

CVE-2019-11218

Disclosure Date: April 24, 2019 (last updated November 27, 2024)
Improper handling of extra parameters in the AccountController (User Profile edit) in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows authenticated users to gain application administrator privileges via additional form parameter submissions.
0
Attacker Value
Unknown

CVE-2019-11217

Disclosure Date: April 24, 2019 (last updated November 27, 2024)
The GitController in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows execution of arbitrary commands in the context of the web server via a crafted http request.
0
Attacker Value
Unknown

CVE-2019-11383

Disclosure Date: April 22, 2019 (last updated November 27, 2024)
An issue was discovered in the Medha WiFi FTP Server application 1.8.3 for Android. An attacker can read the username/password of a valid user via /data/data/com.medhaapps.wififtpserver/shared_prefs/com.medhaapps.wififtpserver_preferences.xml
0
Attacker Value
Unknown

CVE-2019-11401

Disclosure Date: April 22, 2019 (last updated November 27, 2024)
A issue was discovered in SiteServer CMS 6.9.0. It allows remote attackers to execute arbitrary code because an administrator can add the permitted file extension .aassp, which is converted to .asp because the "as" substring is deleted.
0
Attacker Value
Unknown

CVE-2019-8393

Disclosure Date: February 17, 2019 (last updated November 27, 2024)
Hotels_Server through 2018-11-05 has SQL Injection via the API because the controller/api/login.php telephone parameter is mishandled.
0
Attacker Value
Unknown

CVE-2019-8358

Disclosure Date: February 16, 2019 (last updated November 27, 2024)
In Hiawatha before 10.8.4, a remote attacker is able to do directory traversal if AllowDotFiles is enabled.
0
Attacker Value
Unknown

CVE-2019-7648

Disclosure Date: February 08, 2019 (last updated November 27, 2024)
controller/fetchpwd.php and controller/doAction.php in Hotels_Server through 2018-11-05 rely on base64 in an attempt to protect password storage.
0