Show filters
3,812 Total Results
Displaying 351-360 of 3,812
Sort by:
Attacker Value
Unknown

CVE-2023-41453

Disclosure Date: September 27, 2023 (last updated February 25, 2025)
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the cmd parameter in the index.php component.
Attacker Value
Unknown

CVE-2023-41452

Disclosure Date: September 27, 2023 (last updated February 25, 2025)
Cross Site Request Forgery vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the txt parameter in the index.php component.
Attacker Value
Unknown

CVE-2023-41451

Disclosure Date: September 27, 2023 (last updated February 25, 2025)
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the txt parameter in the index.php component.
Attacker Value
Unknown

CVE-2023-41449

Disclosure Date: September 27, 2023 (last updated February 25, 2025)
An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter.
Attacker Value
Unknown

CVE-2023-41448

Disclosure Date: September 27, 2023 (last updated February 25, 2025)
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the ID parameter in the index.php component.
Attacker Value
Unknown

CVE-2023-41445

Disclosure Date: September 27, 2023 (last updated February 25, 2025)
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the index.php component.
Attacker Value
Unknown

CVE-2023-3767

Disclosure Date: September 27, 2023 (last updated February 25, 2025)
An OS command injection vulnerability has been found on EasyPHP Webserver affecting version 14.1. This vulnerability could allow an attacker to get full access to the system by sending a specially crafted exploit to the /index.php?zone=settings parameter.
Attacker Value
Unknown

CVE-2023-41614

Disclosure Date: September 21, 2023 (last updated February 25, 2025)
A stored cross-site scripting (XSS) vulnerability in the Add Animal Details function of Zoo Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description of Animal parameter.
Attacker Value
Unknown

CVE-2023-43274

Disclosure Date: September 21, 2023 (last updated February 25, 2025)
Phpjabbers PHP Shopping Cart 4.2 is vulnerable to SQL Injection via the id parameter.
Attacker Value
Unknown

CVE-2023-40619

Disclosure Date: September 20, 2023 (last updated February 25, 2025)
phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution because user-controlled data is directly passed to the PHP 'unserialize()' function in multiple places. An example is the functionality to manage tables in 'tables.php' where the 'ma[]' POST parameter is deserialized.