Show filters
44 Total Results
Displaying 31-40 of 44
Sort by:
Attacker Value
Unknown

CVE-2022-36672

Disclosure Date: September 01, 2022 (last updated February 24, 2025)
Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file. This vulnerability allows attackers to create a custom user session.
Attacker Value
Unknown

CVE-2022-36671

Disclosure Date: September 01, 2022 (last updated February 24, 2025)
Novel-Plus v3.6.2 was discovered to contain an arbitrary file download vulnerability via the background file download API.
Attacker Value
Unknown

CVE-2022-35121

Disclosure Date: August 17, 2022 (last updated February 24, 2025)
Novel-Plus v3.6.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /service/impl/BookServiceImpl.java.
Attacker Value
Unknown

CVE-2021-42967

Disclosure Date: May 13, 2022 (last updated February 23, 2025)
Unrestricted file upload in /novel-admin/src/main/java/com/java2nb/common/controller/FileController.java in novel-plus all versions allows allows an attacker to upload malicious JSP files.
Attacker Value
Unknown

CVE-2022-28462

Disclosure Date: May 05, 2022 (last updated February 23, 2025)
novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability.
Attacker Value
Unknown

CVE-2021-41921

Disclosure Date: April 28, 2022 (last updated February 23, 2025)
novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks and arbitrary code execution.
Attacker Value
Unknown

CVE-2022-24568

Disclosure Date: February 10, 2022 (last updated February 23, 2025)
Novel-plus v3.6.0 was discovered to be vulnerable to Server-Side Request Forgery (SSRF) via user-supplied crafted input.
Attacker Value
Unknown

CVE-2021-30048

Disclosure Date: April 29, 2021 (last updated February 22, 2025)
Directory Traversal in the fileDownload function in com/java2nb/common/controller/FileController.java in Novel-plus (小说精品屋-plus) 3.5.1 allows attackers to read arbitrary files via the filePath parameter.
Attacker Value
Unknown

CVE-2015-0893

Disclosure Date: March 05, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Maroyaka CGI Maroyaka Relay Novel allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-4047

Disclosure Date: September 11, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Novell Forum (formerly SiteScape Forum) 7.0, 7.1, 7.2, 7.3, and 8.0 allows remote attackers to execute arbitrary TCL code via a modified URL. NOTE: this might overlap CVE-2007-6515.
0