Show filters
42 Total Results
Displaying 31-40 of 42
Sort by:
Attacker Value
Unknown
CVE-2019-9864
Disclosure Date: March 28, 2019 (last updated November 27, 2024)
PHP Scripts Mall Amazon Affiliate Store 2.1.6 allows Parameter Tampering of the payment amount.
0
Attacker Value
Unknown
CVE-2018-14869
Disclosure Date: August 06, 2018 (last updated February 15, 2024)
PHP Template Store Script 3.0.6 allows XSS via the Address line 1, Address Line 2, Bank name, or A/C Holder name field in a profile.
0
Attacker Value
Unknown
CVE-2018-14088
Disclosure Date: July 16, 2018 (last updated November 27, 2024)
An issue was discovered in a smart contract implementation for STeX White List (STE(WL)), an Ethereum token. The contract has an integer overflow. If the owner sets the value of amount to a large number then the "amount * 1000000000000000" will cause an integer overflow in withdrawToFounders().
0
Attacker Value
Unknown
CVE-2015-7879
Disclosure Date: September 11, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in the Stickynote module 7.x before 7.x-1.3 for Drupal allows remote authenticated users with permission to create or edit a stickynote to inject arbitrary web script or HTML via note text on the admin listing page.
0
Attacker Value
Unknown
CVE-2017-5901
Disclosure Date: May 05, 2017 (last updated November 08, 2023)
The State Bank of India State Bank Anywhere app 5.1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-3737
Disclosure Date: July 02, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in templates/defaultheader.php in Lamp Design Storesprite before 7 - 19-06-14, when using the currency selection dropdown, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to brand.php, related to the currencyUrl function.
0
Attacker Value
Unknown
CVE-2007-4307
Disclosure Date: August 13, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Storesprite 7 and earlier allow remote attackers to inject arbitrary web script or HTML via the next parameter to (1) addaddress.php, (2) editshipdetails.php, (3) register.php, or (4) login.php in secure/.
0
Attacker Value
Unknown
CVE-2006-5517
Disclosure Date: October 26, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Rhode Island Open Meetings Filing Application (OMFA) allow remote attackers to execute arbitrary PHP code via a URL in the PROJECT_ROOT parameter to (1) editmeetings/session.php, (2) email/session.php, (3) entityproperties/session.php, or (4) inc/mail.php.
0
Attacker Value
Unknown
CVE-2006-4907
Disclosure Date: September 21, 2006 (last updated October 04, 2023)
OSU 3.11alpha and 3.10a allows remote attackers to obtain sensitive information via a URL to a non-existent file, which displays the web root path in the resulting error message.
0
Attacker Value
Unknown
CVE-2006-4908
Disclosure Date: September 21, 2006 (last updated October 04, 2023)
OSU 3.11alpha and 3.10a allows remote attackers to obtain sensitive information via a URL containing an * (asterisk) wildcard, which displays all matching file and directory information.
0