Show filters
290 Total Results
Displaying 41-50 of 290
Sort by:
Attacker Value
Unknown

CVE-2022-28158

Disclosure Date: March 29, 2022 (last updated February 23, 2025)
A missing permission check in Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Attacker Value
Unknown

CVE-2022-28157

Disclosure Date: March 29, 2022 (last updated February 23, 2025)
Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Item/Configure permission to upload arbitrary files from the Jenkins controller via FTP to an attacker-specified FTP server.
Attacker Value
Unknown

CVE-2022-28156

Disclosure Date: March 29, 2022 (last updated February 23, 2025)
Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Item/Configure permission to copy arbitrary files and directories from the Jenkins controller to the agent workspace.
Attacker Value
Unknown

CVE-2022-28155

Disclosure Date: March 29, 2022 (last updated February 23, 2025)
Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Attacker Value
Unknown

CVE-2022-24563

Disclosure Date: March 03, 2022 (last updated February 23, 2025)
In Genixcms v1.1.11, a stored Cross-Site Scripting (XSS) vulnerability exists in /gxadmin/index.php?page=themes&view=options" via the intro_title and intro_image parameters.
Attacker Value
Unknown

CVE-2022-0571

Disclosure Date: February 14, 2022 (last updated February 23, 2025)
Cross-site Scripting (XSS) - Reflected in GitHub repository phoronix-test-suite/phoronix-test-suite prior to 10.8.2.
Attacker Value
Unknown

CVE-2022-0238

Disclosure Date: January 16, 2022 (last updated February 23, 2025)
phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
Attacker Value
Unknown

CVE-2022-0197

Disclosure Date: January 13, 2022 (last updated February 23, 2025)
phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
Attacker Value
Unknown

CVE-2022-0196

Disclosure Date: January 13, 2022 (last updated February 23, 2025)
phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
Attacker Value
Unknown

CVE-2022-0157

Disclosure Date: January 10, 2022 (last updated February 23, 2025)
phoronix-test-suite is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')