Show filters
529 Total Results
Displaying 311-320 of 529
Sort by:
Attacker Value
Unknown

CVE-2018-10810

Disclosure Date: May 16, 2018 (last updated November 26, 2024)
chat/mobile/index.php in LiveZilla Live Chat 7.0.9.5 and prior is affected by Cross-Site Scripting via the Accept-Language HTTP header.
0
Attacker Value
Unknown

CVE-2017-2840

Disclosure Date: April 24, 2018 (last updated November 26, 2024)
A buffer overflow vulnerability exists in the ISO parsing functionality of EZB Systems UltraISO 9.6.6.3300. A specially crafted .ISO file can cause a vulnerability resulting in potential code execution. An attacker can provide a specific .ISO file to trigger this vulnerability.
Attacker Value
Unknown

CVE-2014-3114

Disclosure Date: April 10, 2018 (last updated November 26, 2024)
The EZPZ One Click Backup (ezpz-one-click-backup) plugin 12.03.10 and earlier for WordPress allows remote attackers to execute arbitrary commands via the cmd parameter to functions/ezpz-archive-cmd.php.
0
Attacker Value
Unknown

CVE-2018-7035

Disclosure Date: April 05, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Gleez CMS 1.2.0 and 2.0 might allow remote attackers (users) to inject JavaScript via HTML content in an editor, which will result in Stored XSS when an Administrator tries to edit the same content, as demonstrated by use of the source editor for HTML mode in an Add Blog action.
0
Attacker Value
Unknown

CVE-2016-10715

Disclosure Date: March 16, 2018 (last updated November 26, 2024)
The Artezio Kanban Board plugin 1.4 revision 1914 for Atlassian Jira has XSS via the Board Name in a Create New Board action, related to an artezioboard/mainPage.jspa?kanbanId=7#/kanban-view URI.
0
Attacker Value
Unknown

CVE-2018-6576

Disclosure Date: February 02, 2018 (last updated November 26, 2024)
SQL Injection exists in Event Manager 1.0 via the event.php id parameter or the page.php slug parameter.
0
Attacker Value
Unknown

CVE-2017-15869

Disclosure Date: January 18, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in knowledgebase.php in LiveZilla before 7.0.8.9 allows remote attackers to inject arbitrary web script or HTML via the search-for parameter.
0
Attacker Value
Unknown

CVE-2017-1000431

Disclosure Date: January 02, 2018 (last updated November 26, 2024)
eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resulting in a risk of attackers injecting scripts which may e.g. steal authentication credentials.
0
Attacker Value
Unknown

CVE-2017-17569

Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Scubez Posty Readymade Classifieds has XSS via the admin/user_activate_submit.php ID parameter.
0
Attacker Value
Unknown

CVE-2017-17568

Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Scubez Posty Readymade Classifieds has Incorrect Access Control for visiting admin/user_activate_submit.php (aka the backend PHP script), which might allow remote attackers to obtain sensitive information via a direct request.
0