Show filters
50 Total Results
Displaying 31-40 of 50
Sort by:
Attacker Value
Unknown
CVE-2019-10078
Disclosure Date: May 20, 2019 (last updated November 08, 2023)
A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking. Initial reporting indicated ReferredPagesPlugin, but further analysis showed that multiple plugins were vulnerable.
0
Attacker Value
Unknown
CVE-2019-10076
Disclosure Date: May 20, 2019 (last updated November 08, 2023)
A carefully crafted malicious attachment could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.
0
Attacker Value
Unknown
CVE-2019-10077
Disclosure Date: May 20, 2019 (last updated November 08, 2023)
A carefully crafted InterWiki link could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.
0
Attacker Value
Unknown
CVE-2019-0225
Disclosure Date: March 28, 2019 (last updated November 08, 2023)
A specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki 2.9.0 to 2.11.0.M2, which could be used by an attacker to obtain registered users' details.
0
Attacker Value
Unknown
CVE-2019-0224
Disclosure Date: March 28, 2019 (last updated November 08, 2023)
In Apache JSPWiki 2.9.0 to 2.11.0.M2, a carefully crafted URL could execute javascript on another user's session. No information could be saved on the server or jspwiki database, nor would an attacker be able to execute js on someone else's browser; only on its own browser.
0
Attacker Value
Unknown
CVE-2018-20242
Disclosure Date: February 11, 2019 (last updated November 08, 2023)
A carefully crafted URL could trigger an XSS vulnerability on Apache JSPWiki, from versions up to 2.10.5, which could lead to session hijacking.
0
Attacker Value
Unknown
CVE-2019-1000004
Disclosure Date: February 04, 2019 (last updated November 27, 2024)
yugandhargangu JspMyAdmin2 version 1.0.6 and earlier contains a Cross Site Scripting (XSS) vulnerability in sidebar and table data that can result in Database fields aren't properly sanitized and allow code injection (Cross-Site Scripting). This attack appears to be exploitable via the payload needs to be stored in the database and the victim must see the db value in question.
0
Attacker Value
Unknown
CVE-2018-20596
Disclosure Date: December 30, 2018 (last updated November 27, 2024)
Jspxcms v9.0.0 allows SSRF.
0
Attacker Value
Unknown
CVE-2018-6609
Disclosure Date: February 05, 2018 (last updated November 26, 2024)
SQL Injection exists in the JSP Tickets 1.1 component for Joomla! via the ticketcode parameter in a ticketlist edit action, or the id parameter in a statuslist (or prioritylist) edit action.
0
Attacker Value
Unknown
CVE-2015-6944
Disclosure Date: September 15, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in JSP/MySQL Administrador Web 1 allows remote attackers to hijack the authentication of users for requests that execute arbitrary SQL commands via the cmd parameter to sys/sys/listaBD2.jsp.
0