Show filters
44 Total Results
Displaying 31-40 of 44
Sort by:
Attacker Value
Unknown
CVE-2022-36672
Disclosure Date: September 01, 2022 (last updated February 24, 2025)
Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file. This vulnerability allows attackers to create a custom user session.
0
Attacker Value
Unknown
CVE-2022-36671
Disclosure Date: September 01, 2022 (last updated February 24, 2025)
Novel-Plus v3.6.2 was discovered to contain an arbitrary file download vulnerability via the background file download API.
0
Attacker Value
Unknown
CVE-2022-35121
Disclosure Date: August 17, 2022 (last updated February 24, 2025)
Novel-Plus v3.6.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /service/impl/BookServiceImpl.java.
0
Attacker Value
Unknown
CVE-2021-42967
Disclosure Date: May 13, 2022 (last updated February 23, 2025)
Unrestricted file upload in /novel-admin/src/main/java/com/java2nb/common/controller/FileController.java in novel-plus all versions allows allows an attacker to upload malicious JSP files.
0
Attacker Value
Unknown
CVE-2022-28462
Disclosure Date: May 05, 2022 (last updated February 23, 2025)
novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability.
0
Attacker Value
Unknown
CVE-2021-41921
Disclosure Date: April 28, 2022 (last updated February 23, 2025)
novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks and arbitrary code execution.
0
Attacker Value
Unknown
CVE-2022-24568
Disclosure Date: February 10, 2022 (last updated February 23, 2025)
Novel-plus v3.6.0 was discovered to be vulnerable to Server-Side Request Forgery (SSRF) via user-supplied crafted input.
0
Attacker Value
Unknown
CVE-2021-30048
Disclosure Date: April 29, 2021 (last updated February 22, 2025)
Directory Traversal in the fileDownload function in com/java2nb/common/controller/FileController.java in Novel-plus (小说精品屋-plus) 3.5.1 allows attackers to read arbitrary files via the filePath parameter.
0
Attacker Value
Unknown
CVE-2015-0893
Disclosure Date: March 05, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Maroyaka CGI Maroyaka Relay Novel allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-4047
Disclosure Date: September 11, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Novell Forum (formerly SiteScape Forum) 7.0, 7.1, 7.2, 7.3, and 8.0 allows remote attackers to execute arbitrary TCL code via a modified URL. NOTE: this might overlap CVE-2007-6515.
0