Show filters
64 Total Results
Displaying 31-40 of 64
Sort by:
Attacker Value
Unknown

CVE-2018-1167

Disclosure Date: April 19, 2018 (last updated November 26, 2024)
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Spotify Music Player 1.0.69.336. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of URI handlers. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5501.
0
Attacker Value
Unknown

CVE-2017-17617

Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
0
Attacker Value
Unknown

CVE-2016-10215

Disclosure Date: February 10, 2017 (last updated November 26, 2024)
An issue was discovered in Fastspot BigTree bigtree-form-builder before 1.2. The vulnerability exists due to insufficient filtration of user-supplied data in multiple HTTP POST parameters passed to a "site/index.php/../../extensions/com.fastspot.form-builder/ajax/redraw-field.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
0
Attacker Value
Unknown

CVE-2015-3319

Disclosure Date: April 16, 2015 (last updated October 05, 2023)
Hotspot Express hotEx Billing Manager 73 does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
0
Attacker Value
Unknown

CVE-2015-2781

Disclosure Date: April 14, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in cgi-bin/hotspotlogin.cgi in Hotspot Express hotEx Billing Manager 73 allows remote attackers to inject arbitrary web script or HTML via the reply parameter.
0
Attacker Value
Unknown

CVE-2014-4552

Disclosure Date: July 02, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in library/includes/payment/paypalexpress/DoDirectPayment.php in the Spotlight (spotlightyour) plugin 4.7 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the paymentType parameter.
0
Attacker Value
Unknown

CVE-2012-5326

Disclosure Date: October 08, 2012 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in admin/function.php in IDevSpot iSupport 1.x allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts via an administrators action.
0
Attacker Value
Unknown

CVE-2012-1779

Disclosure Date: March 19, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in IDevSpot idev-BusinessDirectory 3.0 allows remote attackers to inject arbitrary web script or HTML via the SEARCH parameter to index.php.
0
Attacker Value
Unknown

CVE-2011-3779

Disclosure Date: September 24, 2011 (last updated October 04, 2023)
PhpHostBot 2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/create_acct.php and certain other files.
0
Attacker Value
Unknown

CVE-2010-2319

Disclosure Date: June 17, 2010 (last updated October 04, 2023)
SQL injection vulnerability in index.php in IDevSpot TextAds 2.08 allows remote attackers to execute arbitrary SQL commands via the page parameter.
0