Show filters
529 Total Results
Displaying 311-320 of 529
Sort by:
Attacker Value
Unknown
CVE-2018-10810
Disclosure Date: May 16, 2018 (last updated November 26, 2024)
chat/mobile/index.php in LiveZilla Live Chat 7.0.9.5 and prior is affected by Cross-Site Scripting via the Accept-Language HTTP header.
0
Attacker Value
Unknown
CVE-2017-2840
Disclosure Date: April 24, 2018 (last updated November 26, 2024)
A buffer overflow vulnerability exists in the ISO parsing functionality of EZB Systems UltraISO 9.6.6.3300. A specially crafted .ISO file can cause a vulnerability resulting in potential code execution. An attacker can provide a specific .ISO file to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2014-3114
Disclosure Date: April 10, 2018 (last updated November 26, 2024)
The EZPZ One Click Backup (ezpz-one-click-backup) plugin 12.03.10 and earlier for WordPress allows remote attackers to execute arbitrary commands via the cmd parameter to functions/ezpz-archive-cmd.php.
0
Attacker Value
Unknown
CVE-2018-7035
Disclosure Date: April 05, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Gleez CMS 1.2.0 and 2.0 might allow remote attackers (users) to inject JavaScript via HTML content in an editor, which will result in Stored XSS when an Administrator tries to edit the same content, as demonstrated by use of the source editor for HTML mode in an Add Blog action.
0
Attacker Value
Unknown
CVE-2016-10715
Disclosure Date: March 16, 2018 (last updated November 26, 2024)
The Artezio Kanban Board plugin 1.4 revision 1914 for Atlassian Jira has XSS via the Board Name in a Create New Board action, related to an artezioboard/mainPage.jspa?kanbanId=7#/kanban-view URI.
0
Attacker Value
Unknown
CVE-2018-6576
Disclosure Date: February 02, 2018 (last updated November 26, 2024)
SQL Injection exists in Event Manager 1.0 via the event.php id parameter or the page.php slug parameter.
0
Attacker Value
Unknown
CVE-2017-15869
Disclosure Date: January 18, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in knowledgebase.php in LiveZilla before 7.0.8.9 allows remote attackers to inject arbitrary web script or HTML via the search-for parameter.
0
Attacker Value
Unknown
CVE-2017-1000431
Disclosure Date: January 02, 2018 (last updated November 26, 2024)
eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resulting in a risk of attackers injecting scripts which may e.g. steal authentication credentials.
0
Attacker Value
Unknown
CVE-2017-17569
Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Scubez Posty Readymade Classifieds has XSS via the admin/user_activate_submit.php ID parameter.
0
Attacker Value
Unknown
CVE-2017-17568
Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Scubez Posty Readymade Classifieds has Incorrect Access Control for visiting admin/user_activate_submit.php (aka the backend PHP script), which might allow remote attackers to obtain sensitive information via a direct request.
0