Show filters
48 Total Results
Displaying 31-40 of 48
Sort by:
Attacker Value
Unknown

CVE-2019-15479

Disclosure Date: August 26, 2019 (last updated November 27, 2024)
Status Board 1.1.81 has reflected XSS via dashboard.ts.
0
Attacker Value
Unknown

CVE-2019-15478

Disclosure Date: August 26, 2019 (last updated November 27, 2024)
Status Board 1.1.81 has reflected XSS via logic.ts.
0
Attacker Value
Unknown

CVE-2019-10346

Disclosure Date: July 11, 2019 (last updated October 26, 2023)
A reflected cross site scripting vulnerability in Jenkins Embeddable Build Status Plugin 2.0.1 and earlier allowed attackers inject arbitrary HTML and JavaScript into the response of this plugin.
Attacker Value
Unknown

CVE-2019-12570

Disclosure Date: July 03, 2019 (last updated November 27, 2024)
A SQL injection vulnerability in the Xpert Solution "Server Status by Hostname/IP" plugin 4.6 for WordPress allows an authenticated user to execute arbitrary SQL commands via GET parameters.
0
Attacker Value
Unknown

CVE-2014-5094

Disclosure Date: October 20, 2014 (last updated October 05, 2023)
Status2k allows remote attackers to obtain configuration information via a phpinfo action in a request to status/index.php, which calls the phpinfo function.
0
Attacker Value
Unknown

CVE-2014-5923

Disclosure Date: September 18, 2014 (last updated October 05, 2023)
The Facebook Status Via (aka com.StatusViaAdvanced) application 3.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-5089

Disclosure Date: August 06, 2014 (last updated October 05, 2023)
SQL injection vulnerability in admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary SQL commands via the log parameter.
0
Attacker Value
Unknown

CVE-2014-5090

Disclosure Date: August 06, 2014 (last updated October 05, 2023)
admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the Location field in Add Logs in the Admin Panel.
0
Attacker Value
Unknown

CVE-2014-5088

Disclosure Date: August 06, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Status2k allows remote attackers to inject arbitrary web script or HTML via the username to login.php.
0
Attacker Value
Unknown

CVE-2013-4137

Disclosure Date: October 11, 2013 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in StatusNet 1.0 before 1.0.2 and 1.1.0 allow remote attackers to execute arbitrary SQL commands via vectors related to user lists and "a particular tag format."
0