Show filters
545 Total Results
Displaying 341-350 of 545
Sort by:
Attacker Value
Unknown
CVE-2018-8732
Disclosure Date: March 19, 2018 (last updated November 08, 2023)
Cross-site scripting (XSS) vulnerability in WampServer 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the virtual_del parameter.
0
Attacker Value
Unknown
CVE-2018-7225
Disclosure Date: February 19, 2018 (last updated November 26, 2024)
An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive data or possibly unspecified other impact (e.g., an integer overflow) via specially crafted VNC packets.
0
Attacker Value
Unknown
CVE-2018-5749
Disclosure Date: January 23, 2018 (last updated November 26, 2024)
install.php in Minecraft Servers List Lite before commit c1cd164 and Premium Minecraft Servers List before 2.0.4 does not sanitize input before saving database connection information in connect.php, which might allow remote attackers to execute arbitrary PHP code via the (1) database_server, (2) database_user, (3) database_password, or (4) database_name parameter.
0
Attacker Value
Unknown
CVE-2017-17097
Disclosure Date: January 02, 2018 (last updated November 26, 2024)
gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated request, and then sends e-mail with a predictable (date-based) password to the admin, which makes it easier for remote attackers to obtain access by predicting this new password. This is related to the use of gmdate for password creation in fn_connect.php.
0
Attacker Value
Unknown
CVE-2017-17098
Disclosure Date: January 02, 2018 (last updated November 26, 2024)
The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote attackers to inject arbitrary PHP code via a crafted request that is mishandled during admin log viewing, as demonstrated by <?php system($_GET[cmd]); ?> in a login request.
0
Attacker Value
Unknown
CVE-2017-17932
Disclosure Date: December 28, 2017 (last updated November 26, 2024)
A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow remote attackers to execute arbitrary code and/or cause denial of service on the victim machine/computer via a long string to TCP port 888.
0
Attacker Value
Unknown
CVE-2017-17832
Disclosure Date: December 27, 2017 (last updated November 26, 2024)
ServersCheck Monitoring Software before 14.2.3 is prone to a cross-site scripting vulnerability as user supplied-data is not validated/sanitized when passed in the settings_SMS_ALERT_TYPE parameter, and JavaScript can be executed on settings-save.html (the Settings - SMS Alerts page).
0
Attacker Value
Unknown
CVE-2017-16884
Disclosure Date: December 07, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in MistServer before 2.13 allows remote attackers to inject arbitrary web script or HTML via vectors related to failed authentication requests alerts.
0
Attacker Value
Unknown
CVE-2017-12677
Disclosure Date: August 08, 2017 (last updated November 26, 2024)
IdentityServer3 2.4.x, 2.5.x, and 2.6.x before 2.6.1 has XSS in an Angular expression on the authorize response page, which might allow remote attackers to obtain sensitive information about the IdentityServer authorization response.
0
Attacker Value
Unknown
CVE-2015-1847
Disclosure Date: July 25, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in the web request/response interface in Appserver before 1.0.3 allows remote attackers to read normally inaccessible files via a .. (dot dot) in a crafted URL.
0