Show filters
53 Total Results
Displaying 31-40 of 53
Sort by:
Attacker Value
Unknown
CVE-2016-1587
Disclosure Date: April 22, 2019 (last updated November 27, 2024)
The Snapweb interface before version 0.21.2 was exposing controls to install or remove snap packages without controlling the identity of the user, nor the origin of the connection. An attacker could have used the controls to remotely add a valid, but malicious, snap package, from the Store, potentially using system resources without permission from the legitimate administrator of the system.
0
Attacker Value
Unknown
CVE-2018-17207
Disclosure Date: September 19, 2018 (last updated November 27, 2024)
An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution.
0
Attacker Value
Unknown
CVE-2018-7543
Disclosure Date: March 26, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the json parameter.
0
Attacker Value
Unknown
CVE-2017-1000230
Disclosure Date: November 17, 2017 (last updated November 26, 2024)
The Snap7 Server version 1.4.1 can be crashed when the ItemCount field of the ReadVar or WriteVar functions of the S7 protocol implementation in Snap7 are provided with unexpected input, thus resulting in denial of service attack.
0
Attacker Value
Unknown
CVE-2017-16815
Disclosure Date: November 14, 2017 (last updated November 26, 2024)
installer.php in the Snap Creek Duplicator (WordPress Site Migration & Backup) plugin before 1.2.30 for WordPress has XSS because the values "url_new" (/wp-content/plugins/duplicator/installer/build/view.step4.php) and "logging" (wp-content/plugins/duplicator/installer/build/view.step2.php) are not filtered correctly.
0
Attacker Value
Unknown
CVE-2017-14178
Disclosure Date: November 09, 2017 (last updated November 26, 2024)
In snapd 2.27 through 2.29.2 the 'snap logs' command could be made to call journalctl without match arguments and therefore allow unprivileged, unauthenticated users to bypass systemd-journald's access restrictions.
0
Attacker Value
Unknown
CVE-2014-9262
Disclosure Date: August 07, 2017 (last updated November 26, 2024)
The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files.
0
Attacker Value
Unknown
CVE-2014-9559
Disclosure Date: February 03, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in SnipSnap 0.5.2a, 1.0b1, and 1.0b2 allows remote attackers to inject arbitrary web script or HTML via the query parameter to /snipsnap-search.
0
Attacker Value
Unknown
CVE-2014-7776
Disclosure Date: October 21, 2014 (last updated October 05, 2023)
The Kavita KS (aka com.snaplion.kavitaks) application 2.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-5891
Disclosure Date: September 15, 2014 (last updated October 05, 2023)
The SnipSnap Coupon App (aka com.snipsnap.snipsnapapp) application 1.1.11 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0