Show filters
51 Total Results
Displaying 31-40 of 51
Sort by:
Attacker Value
Unknown

CVE-2018-14730

Disclosure Date: September 21, 2018 (last updated November 27, 2024)
An issue was discovered in Browserify-HMR. Attackers are able to steal developer's code because the origin of requests is not checked by the WebSocket server, which is used for HMR (Hot Module Replacement). Anyone can receive the HMR message sent by the WebSocket server via a ws://127.0.0.1:3123/ connection from any origin.
Attacker Value
Unknown

CVE-2017-17625

Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
Attacker Value
Unknown

CVE-2017-17592

Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Website Auction Marketplace 2.0.5 has SQL Injection via the search.php cat_id parameter.
0
Attacker Value
Unknown

CVE-2014-1750

Disclosure Date: July 01, 2015 (last updated October 05, 2023)
Open redirect vulnerability in nokia-mapsplaces.php in the Nokia Maps & Places plugin 1.6.6 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the href parameter to page/place.html. NOTE: this was originally reported as a cross-site scripting (XSS) vulnerability, but this may be inaccurate.
0
Attacker Value
Unknown

CVE-2009-4428

Disclosure Date: December 28, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the JoomPortfolio (com_joomportfolio) component 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the secid parameter in a showcat action to index.php.
0
Attacker Value
Unknown

CVE-2008-6445

Disclosure Date: March 09, 2009 (last updated October 04, 2023)
Unspecified vulnerability in YourPlace before 1.0.1 has unknown impact and attack vectors, possibly related to improper authentication and the ability to upload arbitrary PHP code. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2009-0531

Disclosure Date: February 11, 2009 (last updated October 04, 2023)
SQL injection vulnerability in gallery/view.asp in A Better Member-Based ASP Photo Gallery before 1.2 allows remote attackers to execute arbitrary SQL commands via the entry parameter.
0
Attacker Value
Unknown

CVE-2008-4512

Disclosure Date: October 09, 2008 (last updated October 04, 2023)
ASP/MS Access Shoutbox, probably 1.1 beta, stores db/shoutdb.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request.
0
Attacker Value
Unknown

CVE-2008-1642

Disclosure Date: April 02, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in Sava's GuestBook 2.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the action parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2008-1644

Disclosure Date: April 02, 2008 (last updated October 04, 2023)
SQL injection vulnerability in viewlinks.php in Sava's Link Manager 2.0 allows remote attackers to execute arbitrary SQL commands via the category parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0