Show filters
43 Total Results
Displaying 31-40 of 43
Sort by:
Attacker Value
Unknown

CVE-2018-19598

Disclosure Date: December 19, 2018 (last updated November 27, 2024)
Statamic 2.10.3 allows XSS via First Name or Last Name to the /users URI in an 'Add new user' request.
0
Attacker Value
Unknown

CVE-2018-12560

Disclosure Date: June 19, 2018 (last updated November 26, 2024)
An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. Arbitrary unmounts can be performed by regular users via directory traversal sequences such as a home/../sys/kernel substring.
0
Attacker Value
Unknown

CVE-2018-12561

Disclosure Date: June 19, 2018 (last updated November 26, 2024)
An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. A regular user can inject additional mount options such as file_mode= by manipulating (for example) the domain parameter of the samba URL.
0
Attacker Value
Unknown

CVE-2018-12562

Disclosure Date: June 19, 2018 (last updated November 26, 2024)
An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The wrapper script 'mount.cifs.wrapper' uses the shell to forward the arguments to the actual mount.cifs binary. The shell evaluates wildcards (such as in an injected string:/home/../tmp/* string).
0
Attacker Value
Unknown

CVE-2018-12559

Disclosure Date: June 19, 2018 (last updated November 26, 2024)
An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The mount target path check in mounter.cpp `mpOk()` is insufficient. A regular user can consequently mount a CIFS filesystem anywhere (e.g., outside of the /home directory tree) by passing directory traversal sequences such as a home/../usr substring.
0
Attacker Value
Unknown

CVE-2017-11422

Disclosure Date: July 24, 2017 (last updated November 26, 2024)
Statamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called. Problematic methods include reset password, create new account, create new role, etc.
Attacker Value
Unknown

CVE-2017-11349

Disclosure Date: July 17, 2017 (last updated November 26, 2024)
dataTaker DT8x dEX 1.72.007 allows remote attackers to compose programs or schedules, for purposes such as sending e-mail messages or making outbound connections to FTP servers for uploading data.
0
Attacker Value
Unknown

CVE-2017-11165

Disclosure Date: July 12, 2017 (last updated November 26, 2024)
dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for the /services/getFile.cmd?userfile=config.xml URI.
0
Attacker Value
Unknown

CVE-2014-9175

Disclosure Date: December 02, 2014 (last updated October 05, 2023)
SQL injection vulnerability in wpdatatables.php in the wpDataTables plugin 1.5.3 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the table_id parameter in a get_wdtable action to wp-admin/admin-ajax.php.
0
Attacker Value
Unknown

CVE-2014-7559

Disclosure Date: October 20, 2014 (last updated October 05, 2023)
The InstaTalks (aka com.natrobit.instatalks) application 1.3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0