Show filters
46 Total Results
Displaying 31-40 of 46
Sort by:
Attacker Value
Unknown
CVE-2021-24251
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator update arbitrary payment history, such as change their status (from pending to completed to example)
0
Attacker Value
Unknown
CVE-2021-24178
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 suffered from Cross-Site Request Forgery issues, allowing an attacker to make a logged in administrator add, edit or delete form fields, which could also lead to Stored Cross-Site Scripting issues.
0
Attacker Value
Unknown
CVE-2020-24699
Disclosure Date: August 31, 2020 (last updated February 22, 2025)
The Chamber Dashboard Business Directory plugin 3.2.8 for WordPress allows XSS.
0
Attacker Value
Unknown
CVE-2016-0770
Disclosure Date: March 16, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in includes/admin/pages/manage.php in the Connections Business Directory plugin before 8.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s variable.
0
Attacker Value
Unknown
CVE-2014-7065
Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The Nigerias Business Directory (aka com.wNigeriasBusinessDirectory) application 0.70.13414.17619 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-4599
Disclosure Date: July 02, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in forms/search.php in the WP-Business Directory (wp-ttisbdir) plugin 1.0.2 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) edit, (2) search_term, (3) page_id, (4) page, or (5) page_links parameter.
0
Attacker Value
Unknown
CVE-2012-6589
Disclosure Date: August 25, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in search.php in MYRE Business Directory allows remote attackers to inject arbitrary web script or HTML via the look parameter.
0
Attacker Value
Unknown
CVE-2012-6588
Disclosure Date: August 25, 2013 (last updated October 05, 2023)
SQL injection vulnerability in links.php in MYRE Business Directory allows remote attackers to execute arbitrary SQL commands via the cat parameter.
0
Attacker Value
Unknown
CVE-2010-4969
Disclosure Date: November 01, 2011 (last updated October 04, 2023)
SQL injection vulnerability in articlesdetails.php in BrotherScripts (BS) Business Directory allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown
CVE-2010-1092
Disclosure Date: March 24, 2010 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in login.php in ScriptsFeed Business Directory Software allow remote attackers to execute arbitrary SQL commands via the (1) us and (2) ps parameters.
0