Show filters
167 Total Results
Displaying 41-50 of 167
Sort by:
Attacker Value
Unknown
CVE-2023-22856
Disclosure Date: March 06, 2023 (last updated October 08, 2023)
A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in the security context of a blog visitor through an upload of a specially crafted file.
0
Attacker Value
Unknown
CVE-2023-0650
Disclosure Date: February 02, 2023 (last updated October 20, 2023)
A vulnerability was found in YAFNET up to 3.1.11 and classified as problematic. This issue affects some unknown processing of the component Signature Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.1.12 is able to address this issue. The identifier of the patch is a1442a2bacc3335461b44c250e81f8d99c60735f. It is recommended to upgrade the affected component. The identifier VDB-220037 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-0549
Disclosure Date: January 27, 2023 (last updated October 20, 2023)
A vulnerability, which was classified as problematic, has been found in YAFNET up to 3.1.10. This issue affects some unknown processing of the file /forum/PostPrivateMessage of the component Private Message Handler. The manipulation of the argument subject/message leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.1.11 is able to address this issue. The identifier of the patch is 2237a9d552e258a43570bb478a92a5505e7c8797. It is recommended to upgrade the affected component. The identifier VDB-219665 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2022-41417
Disclosure Date: January 18, 2023 (last updated October 08, 2023)
BlogEngine.NET v3.3.8.0 allows an attacker to create any folder with "files" prefix under ~/App_Data/.
0
Attacker Value
Unknown
CVE-2022-41418
Disclosure Date: December 19, 2022 (last updated October 08, 2023)
An issue in the component BlogEngine/BlogEngine.NET/AppCode/Api/UploadController.cs of BlogEngine.NET v3.3.8.0 allows attackers to execute arbitrary code via uploading a crafted PNG file.
0
Attacker Value
Unknown
CVE-2022-47514
Disclosure Date: December 18, 2022 (last updated October 08, 2023)
An XML external entity (XXE) injection vulnerability in XML-RPC.NET before 2.5.0 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, as demonstrated by a pingback.aspx POST request.
0
Attacker Value
Unknown
CVE-2022-41479
Disclosure Date: October 18, 2022 (last updated August 03, 2024)
The DevExpress Resource Handler (ASPxHttpHandlerModule) in DevExpress ASP.NET Web Forms Build v19.2.3 does not verify the referenced objects in the /DXR.axd?r= HTTP GET parameter. This leads to an Insecure Direct Object References (IDOR) vulnerability which allows attackers to access the application source code. NOTE: the vendor disputes this because the retrieved source code is only the DevExpress client-side application code that is, of course, intentionally readable by web browsers (a site's custom code and data is never accessible via an IDOR approach).
0
Attacker Value
Unknown
CVE-2018-18447
Disclosure Date: October 12, 2022 (last updated October 08, 2023)
dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 2 of 2).
0
Attacker Value
Unknown
CVE-2018-18446
Disclosure Date: October 12, 2022 (last updated October 08, 2023)
dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 1 of 2).
0
Attacker Value
Unknown
CVE-2022-36600
Disclosure Date: September 02, 2022 (last updated October 08, 2023)
BlogEngine v3.3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /blogengine/api/posts. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field.
0