Show filters
80 Total Results
Displaying 41-50 of 80
Sort by:
Attacker Value
Unknown

CVE-2019-13507

Disclosure Date: July 11, 2019 (last updated November 27, 2024)
hidea.com AZ Admin 1.0 has news_det.php?cod= SQL Injection.
0
Attacker Value
Unknown

CVE-2019-12047

Disclosure Date: May 13, 2019 (last updated November 27, 2024)
Gridea v0.8.0 has an XSS vulnerability through which the Nodejs module can be called to achieve arbitrary code execution, as demonstrated by child_process.exec and the "<img src=# onerror='eval(new Buffer(" substring.
0
Attacker Value
Unknown

CVE-2018-1000809

Disclosure Date: October 08, 2018 (last updated November 27, 2024)
privacyIDEA version 2.23.1 and earlier contains a Improper Input Validation vulnerability in token validation api that can result in Denial-of-Service. This attack appear to be exploitable via http request with user=<space>&pass= to /validate/check url. This vulnerability appears to have been fixed in 2.23.2.
0
Attacker Value
Unknown

CVE-2018-16372

Disclosure Date: September 03, 2018 (last updated November 27, 2024)
The issue was discovered in IdeaCMS through 2016-04-30. There is reflected XSS via the index.php?c=content&a=search kw parameter. NOTE: this product is discontinued.
0
Attacker Value
Unknown

CVE-2018-13706

Disclosure Date: July 09, 2018 (last updated November 27, 2024)
The mintToken function of a smart contract implementation for IdeaCoin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
0
Attacker Value
Unknown

CVE-2018-5263

Disclosure Date: January 08, 2018 (last updated November 26, 2024)
The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS.
0
Attacker Value
Unknown

CVE-2015-7324

Disclosure Date: December 27, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in helpers/comment.php in the StackIdeas Komento (com_komento) component before 2.0.5 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) img or (2) url tag of a new comment.
0
Attacker Value
Unknown

CVE-2017-9424

Disclosure Date: June 22, 2017 (last updated November 26, 2024)
IdeaBlade Breeze Breeze.Server.NET before 1.6.5 allows remote attackers to execute arbitrary code, related to use of TypeNameHandling in JSON deserialization.
0
Attacker Value
Unknown

CVE-2013-4979

Disclosure Date: January 31, 2014 (last updated October 05, 2023)
Buffer overflow in the gldll32.dll module in EPS Viewer 3.2 and earlier allows remote attackers to execute arbitrary code via a crafted EPS file.
0
Attacker Value
Unknown

CVE-2014-1837

Disclosure Date: January 30, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the StackIdeas Komento (com_komento) component before 1.7.4 for Joomla! allows remote attackers to inject arbitrary web script or HTML via vectors related to "checking new comments."
0