Show filters
80 Total Results
Displaying 41-50 of 80
Sort by:
Attacker Value
Unknown
CVE-2019-13507
Disclosure Date: July 11, 2019 (last updated November 27, 2024)
hidea.com AZ Admin 1.0 has news_det.php?cod= SQL Injection.
0
Attacker Value
Unknown
CVE-2019-12047
Disclosure Date: May 13, 2019 (last updated November 27, 2024)
Gridea v0.8.0 has an XSS vulnerability through which the Nodejs module can be called to achieve arbitrary code execution, as demonstrated by child_process.exec and the "<img src=# onerror='eval(new Buffer(" substring.
0
Attacker Value
Unknown
CVE-2018-1000809
Disclosure Date: October 08, 2018 (last updated November 27, 2024)
privacyIDEA version 2.23.1 and earlier contains a Improper Input Validation vulnerability in token validation api that can result in Denial-of-Service. This attack appear to be exploitable via http request with user=<space>&pass= to /validate/check url. This vulnerability appears to have been fixed in 2.23.2.
0
Attacker Value
Unknown
CVE-2018-16372
Disclosure Date: September 03, 2018 (last updated November 27, 2024)
The issue was discovered in IdeaCMS through 2016-04-30. There is reflected XSS via the index.php?c=content&a=search kw parameter. NOTE: this product is discontinued.
0
Attacker Value
Unknown
CVE-2018-13706
Disclosure Date: July 09, 2018 (last updated November 27, 2024)
The mintToken function of a smart contract implementation for IdeaCoin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
0
Attacker Value
Unknown
CVE-2018-5263
Disclosure Date: January 08, 2018 (last updated November 26, 2024)
The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS.
0
Attacker Value
Unknown
CVE-2015-7324
Disclosure Date: December 27, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in helpers/comment.php in the StackIdeas Komento (com_komento) component before 2.0.5 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) img or (2) url tag of a new comment.
0
Attacker Value
Unknown
CVE-2017-9424
Disclosure Date: June 22, 2017 (last updated November 26, 2024)
IdeaBlade Breeze Breeze.Server.NET before 1.6.5 allows remote attackers to execute arbitrary code, related to use of TypeNameHandling in JSON deserialization.
0
Attacker Value
Unknown
CVE-2013-4979
Disclosure Date: January 31, 2014 (last updated October 05, 2023)
Buffer overflow in the gldll32.dll module in EPS Viewer 3.2 and earlier allows remote attackers to execute arbitrary code via a crafted EPS file.
0
Attacker Value
Unknown
CVE-2014-1837
Disclosure Date: January 30, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the StackIdeas Komento (com_komento) component before 1.7.4 for Joomla! allows remote attackers to inject arbitrary web script or HTML via vectors related to "checking new comments."
0