Show filters
43 Total Results
Displaying 31-40 of 43
Sort by:
Attacker Value
Unknown
CVE-2018-19598
Disclosure Date: December 19, 2018 (last updated November 27, 2024)
Statamic 2.10.3 allows XSS via First Name or Last Name to the /users URI in an 'Add new user' request.
0
Attacker Value
Unknown
CVE-2018-12560
Disclosure Date: June 19, 2018 (last updated November 26, 2024)
An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. Arbitrary unmounts can be performed by regular users via directory traversal sequences such as a home/../sys/kernel substring.
0
Attacker Value
Unknown
CVE-2018-12561
Disclosure Date: June 19, 2018 (last updated November 26, 2024)
An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. A regular user can inject additional mount options such as file_mode= by manipulating (for example) the domain parameter of the samba URL.
0
Attacker Value
Unknown
CVE-2018-12562
Disclosure Date: June 19, 2018 (last updated November 26, 2024)
An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The wrapper script 'mount.cifs.wrapper' uses the shell to forward the arguments to the actual mount.cifs binary. The shell evaluates wildcards (such as in an injected string:/home/../tmp/* string).
0
Attacker Value
Unknown
CVE-2018-12559
Disclosure Date: June 19, 2018 (last updated November 26, 2024)
An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The mount target path check in mounter.cpp `mpOk()` is insufficient. A regular user can consequently mount a CIFS filesystem anywhere (e.g., outside of the /home directory tree) by passing directory traversal sequences such as a home/../usr substring.
0
Attacker Value
Unknown
CVE-2017-11422
Disclosure Date: July 24, 2017 (last updated November 26, 2024)
Statamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called. Problematic methods include reset password, create new account, create new role, etc.
0
Attacker Value
Unknown
CVE-2017-11349
Disclosure Date: July 17, 2017 (last updated November 26, 2024)
dataTaker DT8x dEX 1.72.007 allows remote attackers to compose programs or schedules, for purposes such as sending e-mail messages or making outbound connections to FTP servers for uploading data.
0
Attacker Value
Unknown
CVE-2017-11165
Disclosure Date: July 12, 2017 (last updated November 26, 2024)
dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for the /services/getFile.cmd?userfile=config.xml URI.
0
Attacker Value
Unknown
CVE-2014-9175
Disclosure Date: December 02, 2014 (last updated October 05, 2023)
SQL injection vulnerability in wpdatatables.php in the wpDataTables plugin 1.5.3 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the table_id parameter in a get_wdtable action to wp-admin/admin-ajax.php.
0
Attacker Value
Unknown
CVE-2014-7559
Disclosure Date: October 20, 2014 (last updated October 05, 2023)
The InstaTalks (aka com.natrobit.instatalks) application 1.3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0