Show filters
121 Total Results
Displaying 31-40 of 121
Sort by:
Attacker Value
Unknown

CVE-2023-4308

Disclosure Date: August 15, 2023 (last updated October 08, 2023)
The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user-submitted-content’ parameter in versions up to, and including, 20230809 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2023-33553

Disclosure Date: June 07, 2023 (last updated October 08, 2023)
An issue in Planet Technologies WDRT-1800AX v1.01-CP21 allows attackers to bypass authentication and escalate privileges to root via manipulation of the LoginStatus cookie.
Attacker Value
Unknown

CVE-2019-25138

Disclosure Date: June 07, 2023 (last updated October 08, 2023)
The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the usp_check_images function in versions up to, and including, 20190312. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
Attacker Value
Unknown

CVE-2023-32303

Disclosure Date: May 12, 2023 (last updated October 08, 2023)
Planet is software that provides satellite data. The secret file stores the user's Planet API authentication information. It should only be accessible by the user, but before version 2.0.1, its permissions allowed the user's group and non-group to read the file as well. This issue was patched in version 2.0.1. As a workaround, set the secret file permissions to only user read/write by hand.
Attacker Value
Unknown

CVE-2023-26517

Disclosure Date: May 06, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jeff Starr Dashboard Widgets Suite plugin <= 3.2.1 versions.
Attacker Value
Unknown

CVE-2014-125080

Disclosure Date: January 16, 2023 (last updated October 20, 2023)
A vulnerability has been found in frontaccounting faplanet and classified as critical. This vulnerability affects unknown code. The manipulation leads to path traversal. The patch is identified as a5dcd87f46080a624b1a9ad4b0dd035bbd24ac50. It is recommended to apply a patch to fix this issue. VDB-218398 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-45896

Disclosure Date: December 25, 2022 (last updated October 08, 2023)
Planet eStream before 6.72.10.07 allows unauthenticated upload of arbitrary files: Choose a Video / Related Media or Upload Document. Upload2.ashx can be used, or Ajax.asmx/ProcessUpload2. This leads to remote code execution.
Attacker Value
Unknown

CVE-2022-45895

Disclosure Date: December 25, 2022 (last updated October 08, 2023)
Planet eStream before 6.72.10.07 discloses sensitive information, related to the ON cookie (findable in HTML source code for Default.aspx in some situations) and the WhoAmI endpoint (e.g., path disclosure).
Attacker Value
Unknown

CVE-2022-45894

Disclosure Date: December 25, 2022 (last updated October 08, 2023)
GetFile.aspx in Planet eStream before 6.72.10.07 allows ..\ directory traversal to read arbitrary local files.
Attacker Value
Unknown

CVE-2022-45893

Disclosure Date: December 25, 2022 (last updated October 08, 2023)
Planet eStream before 6.72.10.07 allows a low-privileged user to gain access to administrative and high-privileged user accounts by changing the value of the ON cookie. A brute-force attack can calculate a value that provides permanent access.