Show filters
51 Total Results
Displaying 31-40 of 51
Sort by:
Attacker Value
Unknown
CVE-2017-18536
Disclosure Date: August 21, 2019 (last updated November 27, 2024)
The stop-user-enumeration plugin before 1.3.8 for WordPress has XSS.
0
Attacker Value
Unknown
CVE-2017-1000226
Disclosure Date: November 17, 2017 (last updated November 26, 2024)
Stop User Enumeration 1.3.8 allows user enumeration via the REST API
0
Attacker Value
Unknown
CVE-2008-6977
Disclosure Date: August 19, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in album.asp in Full Revolution aspWebAlbum 3.2 allows remote attackers to inject arbitrary web script or HTML via the message parameter in a summary action.
0
Attacker Value
Unknown
CVE-2008-6978
Disclosure Date: August 19, 2009 (last updated October 04, 2023)
Unrestricted file upload vulnerability in Full Revolution aspWebAlbum 3.2 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in pics/, related to the uploadmedia action in album.asp.
0
Attacker Value
Unknown
CVE-2009-1223
Disclosure Date: April 02, 2009 (last updated October 04, 2023)
aspWebCalendar Free Edition stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for calendar/calendar.mdb.
0
Attacker Value
Unknown
CVE-2008-2832
Disclosure Date: June 24, 2008 (last updated October 04, 2023)
Unrestricted file upload vulnerability in calendar_admin.asp in Full Revolution aspWebCalendar 2008 allows remote attackers to upload and execute arbitrary code via the FILE1 parameter in an uploadfileprocess action, probably followed by a direct request to the file in calendar/eventimages/.
0
Attacker Value
Unknown
CVE-2008-1350
Disclosure Date: March 17, 2008 (last updated October 04, 2023)
SQL injection vulnerability in kb.php in Fully Modded phpBB (phpbbfm) 80220 allows remote attackers to execute arbitrary SQL commands via the k parameter in an article action.
0
Attacker Value
Unknown
CVE-2007-5068
Disclosure Date: September 24, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in phpFullAnnu (PFA) 6.0 allows remote attackers to execute arbitrary SQL commands via the mod parameter.
0
Attacker Value
Unknown
CVE-2007-3299
Disclosure Date: June 20, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in AWFFull before 3.7.4, when AllSearchStr (aka the All Search Terms report) is enabled, allows remote attackers to inject arbitrary web script or HTML via a search string.
0
Attacker Value
Unknown
CVE-2007-2257
Disclosure Date: April 25, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in subscp.php in Fully Modded phpBB2 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
0