Show filters
529 Total Results
Displaying 321-330 of 529
Sort by:
Attacker Value
Unknown

CVE-2017-17567

Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Scubez Posty Readymade Classifieds has SQL Injection via the admin/user_activate_submit.php ID parameter.
0
Attacker Value
Unknown

CVE-2017-17111

Disclosure Date: December 11, 2017 (last updated November 26, 2024)
Posty Readymade Classifieds Script 1.0 allows an attacker to inject SQL commands via a listings.php?catid= or ads-details.php?ID= request.
0
Attacker Value
Unknown

CVE-2017-14943

Disclosure Date: October 10, 2017 (last updated November 26, 2024)
Trapeze TransitMaster is vulnerable to information disclosure (emails / hashed passwords) via a modified userID field in JSON data to ManageSubscriber.aspx/GetSubscriber. NOTE: this software is independently deployed at multiple municipal transit systems; it is not found exclusively on the "webwatch.(REDACTED).com" server mentioned in the reference.
0
Attacker Value
Unknown

CVE-2017-1000250

Disclosure Date: September 12, 2017 (last updated November 26, 2024)
All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory. This vulnerability lies in the processing of SDP search attribute requests.
0
Attacker Value
Unknown

CVE-2017-14146

Disclosure Date: September 05, 2017 (last updated November 26, 2024)
HelpDEZk 1.1.1 allows remote authenticated users to execute arbitrary PHP code by uploading a .php attachment and then requesting it in the helpdezk\app\uploads\helpdezk\attachments\ directory.
0
Attacker Value
Unknown

CVE-2017-14145

Disclosure Date: September 05, 2017 (last updated November 26, 2024)
HelpDEZk 1.1.1 has SQL Injection in app\modules\admin\controllers\loginController.php via the admin/login/getWarningInfo/id/ PATH_INFO, related to the selectWarning function.
0
Attacker Value
Unknown

CVE-2016-7837

Disclosure Date: June 09, 2017 (last updated November 26, 2024)
Buffer overflow in BlueZ 5.41 and earlier allows an attacker to execute arbitrary code via the parse_line function used in some userland utilities.
0
Attacker Value
Unknown

CVE-2017-7447

Disclosure Date: April 05, 2017 (last updated November 26, 2024)
HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code.
0
Attacker Value
Unknown

CVE-2017-7446

Disclosure Date: April 05, 2017 (last updated November 26, 2024)
HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges.
0
Attacker Value
Unknown

CVE-2017-5591

Disclosure Date: February 09, 2017 (last updated November 26, 2024)
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for SleekXMPP up to 1.3.1 and Slixmpp all versions up to 1.2.3, as bundled in poezio (0.8 - 0.10) and other products.