Show filters
57 Total Results
Displaying 41-50 of 57
Sort by:
Attacker Value
Unknown
CVE-2019-14800
Disclosure Date: August 15, 2019 (last updated November 27, 2024)
The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription list in CSV format via the wp-admin/admin-post.php?page=fvplayer&fv-email-export=1 URI.
0
Attacker Value
Unknown
CVE-2019-14801
Disclosure Date: August 09, 2019 (last updated November 27, 2024)
The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection.
0
Attacker Value
Unknown
CVE-2019-14799
Disclosure Date: August 09, 2019 (last updated November 27, 2024)
The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS.
0
Attacker Value
Unknown
CVE-2019-13573
Disclosure Date: July 17, 2019 (last updated November 27, 2024)
A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.
0
Attacker Value
Unknown
CVE-2018-0642
Disclosure Date: September 07, 2018 (last updated November 27, 2024)
Cross-site scripting vulnerability in FV Flowplayer Video Player 6.1.2 to 6.6.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-4351
Disclosure Date: June 15, 2015 (last updated October 05, 2023)
The Spider Video Player module for Drupal allows remote authenticated users with the "access Spider Video Player administration" permission to delete arbitrary files via a crafted URL.
0
Attacker Value
Unknown
CVE-2015-4352
Disclosure Date: June 15, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the Spider Video Player module for Drupal allows remote attackers to hijack the authentication of administrators for requests that delete videos via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-8584
Disclosure Date: November 04, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Web Dorado Spider Video Player (aka WordPress Video Player) plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-5956
Disclosure Date: September 18, 2014 (last updated October 05, 2023)
The VPlayer Video Player (aka me.abitno.vplayer.t) application 3.2.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-5180
Disclosure Date: August 06, 2014 (last updated October 05, 2023)
SQL injection vulnerability in the videos page in the HDW Player Plugin (hdw-player-video-player-video-gallery) 2.4.2 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter in the edit action to wp-admin/admin.php.
0