Show filters
64 Total Results
Displaying 31-40 of 64
Sort by:
Attacker Value
Unknown
CVE-2018-1167
Disclosure Date: April 19, 2018 (last updated November 26, 2024)
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Spotify Music Player 1.0.69.336. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of URI handlers. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5501.
0
Attacker Value
Unknown
CVE-2017-17617
Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
0
Attacker Value
Unknown
CVE-2016-10215
Disclosure Date: February 10, 2017 (last updated November 26, 2024)
An issue was discovered in Fastspot BigTree bigtree-form-builder before 1.2. The vulnerability exists due to insufficient filtration of user-supplied data in multiple HTTP POST parameters passed to a "site/index.php/../../extensions/com.fastspot.form-builder/ajax/redraw-field.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
0
Attacker Value
Unknown
CVE-2015-3319
Disclosure Date: April 16, 2015 (last updated October 05, 2023)
Hotspot Express hotEx Billing Manager 73 does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
0
Attacker Value
Unknown
CVE-2015-2781
Disclosure Date: April 14, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in cgi-bin/hotspotlogin.cgi in Hotspot Express hotEx Billing Manager 73 allows remote attackers to inject arbitrary web script or HTML via the reply parameter.
0
Attacker Value
Unknown
CVE-2014-4552
Disclosure Date: July 02, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in library/includes/payment/paypalexpress/DoDirectPayment.php in the Spotlight (spotlightyour) plugin 4.7 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the paymentType parameter.
0
Attacker Value
Unknown
CVE-2012-5326
Disclosure Date: October 08, 2012 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in admin/function.php in IDevSpot iSupport 1.x allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts via an administrators action.
0
Attacker Value
Unknown
CVE-2012-1779
Disclosure Date: March 19, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in IDevSpot idev-BusinessDirectory 3.0 allows remote attackers to inject arbitrary web script or HTML via the SEARCH parameter to index.php.
0
Attacker Value
Unknown
CVE-2011-3779
Disclosure Date: September 24, 2011 (last updated October 04, 2023)
PhpHostBot 2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/create_acct.php and certain other files.
0
Attacker Value
Unknown
CVE-2010-2319
Disclosure Date: June 17, 2010 (last updated October 04, 2023)
SQL injection vulnerability in index.php in IDevSpot TextAds 2.08 allows remote attackers to execute arbitrary SQL commands via the page parameter.
0