Show filters
38 Total Results
Displaying 31-38 of 38
Sort by:
Attacker Value
Unknown
CVE-2020-9390
Disclosure Date: February 03, 2021 (last updated February 22, 2025)
SquaredUp allowed Stored XSS before version 4.6.0. A user was able to create a dashboard that executed malicious content in iframe or by uploading an SVG that contained a script.
0
Attacker Value
Unknown
CVE-2020-9388
Disclosure Date: February 03, 2021 (last updated February 22, 2025)
CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administrator executing arbitrary code in a HTML dashboard tile via a crafted HTML page, or by uploading a malicious SVG payload into a dashboard.
0
Attacker Value
Unknown
CVE-2014-6013
Disclosure Date: September 22, 2014 (last updated October 05, 2023)
The nuSquare (aka tw.com.nuphoto.nusquare) application 1.0.78 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2013-5036
Disclosure Date: May 27, 2014 (last updated October 05, 2023)
The Square Squash allows remote attackers to execute arbitrary code via a YAML document in the (1) namespace parameter to the deobfuscation function or (2) sourcemap parameter to the sourcemap function in app/controllers/api/v1_controller.rb.
0
Attacker Value
Unknown
CVE-2013-2709
Disclosure Date: April 26, 2013 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the FourSquare Checkins plugin before 1.3 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
0
Attacker Value
Unknown
CVE-2008-2893
Disclosure Date: June 27, 2008 (last updated October 04, 2023)
SQL injection vulnerability in news.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-2532.
0
Attacker Value
Unknown
CVE-2008-0634
Disclosure Date: February 06, 2008 (last updated October 04, 2023)
Buffer overflow in the NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1, as used in Sejoong Namo ActiveSquare6, allows remote attackers to execute arbitrary code via a long argument to the Install method, a different vulnerability than CVE-2008-0551.
0
Attacker Value
Unknown
CVE-2008-0551
Disclosure Date: February 01, 2008 (last updated October 04, 2023)
The NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1 and earlier in Namo Web Editor in Sejoong Namo ActiveSquare 6 allows remote attackers to execute arbitrary code via a URL in the argument to the Install method. NOTE: some of these details are obtained from third party information.
0