Show filters
733 Total Results
Displaying 401-410 of 733
Sort by:
Attacker Value
Unknown

CVE-2018-9017

Disclosure Date: March 25, 2018 (last updated November 26, 2024)
dsmall v20180320 allows XSS via the member search box at the public/index.php/home/membersnsfriend/findlist.html URI.
0
Attacker Value
Unknown

CVE-2018-9014

Disclosure Date: March 25, 2018 (last updated November 26, 2024)
dsmall v20180320 allows physical path leakage via a public/index.php/home/predeposit/index.html?pdr_sn= request.
0
Attacker Value
Unknown

CVE-2018-8906

Disclosure Date: March 22, 2018 (last updated November 26, 2024)
dsmall v20180320 has XSS via a crafted street address to public/index.php/home/memberaddress/index.html, which is mishandled at public/index.php/home/memberaddress/edit/address_id/2.html.
0
Attacker Value
Unknown

CVE-2017-18231

Disclosure Date: March 14, 2018 (last updated November 26, 2024)
An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vulnerability was found in the function ReadEnhMetaFile in coders/emf.c, which allows attackers to cause a denial of service via a crafted file.
0
Attacker Value
Unknown

CVE-2017-18229

Disclosure Date: March 14, 2018 (last updated November 26, 2024)
An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerability was found in the function ReadTIFFImage in coders/tiff.c, which allows attackers to cause a denial of service via a crafted file, because file size is not properly used to restrict scanline, strip, and tile allocations.
0
Attacker Value
Unknown

CVE-2017-18230

Disclosure Date: March 14, 2018 (last updated November 26, 2024)
An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vulnerability was found in the function ReadCINEONImage in coders/cineon.c, which allows attackers to cause a denial of service via a crafted file.
0
Attacker Value
Unknown

CVE-2018-1000092

Disclosure Date: March 13, 2018 (last updated November 26, 2024)
CMS Made Simple version versions 2.2.5 contains a Cross ite Request Forgery (CSRF) vulnerability in Admin profile page that can result in Details can be found here http://dev.cmsmadesimple.org/bug/view/11715. This attack appear to be exploitable via A specially crafted web page. This vulnerability appears to have been fixed in 2.2.6.
0
Attacker Value
Unknown

CVE-2018-1000094

Disclosure Date: March 13, 2018 (last updated November 26, 2024)
CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows an authenticated admin that has access to the file manager to execute code on the server. This attack appear to be exploitable via File upload -> copy to any extension.
0
Attacker Value
Unknown

CVE-2018-7893

Disclosure Date: March 12, 2018 (last updated November 26, 2024)
CMS Made Simple (CMSMS) 2.2.6 has stored XSS in admin/moduleinterface.php via the metadata parameter.
0
Attacker Value
Unknown

CVE-2018-8058

Disclosure Date: March 12, 2018 (last updated November 26, 2024)
CMS Made Simple (CMSMS) 2.2.6 has XSS in admin/moduleinterface.php via the pagedata parameter.
0