Show filters
545 Total Results
Displaying 411-420 of 545
Sort by:
Attacker Value
Unknown
CVE-2013-4240
Disclosure Date: April 02, 2014 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add new testimonials via the hms-testimonials-addnew page, (2) add new groups via the hms-testimonials-addnewgroup page, (3) change default settings via the hms-testimonials-settings page, (4) change advanced settings via the hms-testimonials-settings-advanced page, (5) change custom fields settings via the hms-testimonials-settings-fields page, or (6) change template settings via the hms-testimonials-templates-new page to wp-admin/admin.php.
0
Attacker Value
Unknown
CVE-2013-7149
Disclosure Date: December 28, 2013 (last updated October 05, 2023)
SQL injection vulnerability in www/delivery/axmlrpc.php (aka the XML-RPC delivery invocation script) in Revive Adserver before 3.0.2, and OpenX Source 2.8.11 and earlier, allows remote attackers to execute arbitrary SQL commands via the what parameter to an XML-RPC method.
0
Attacker Value
Unknown
CVE-2013-2790
Disclosure Date: August 13, 2013 (last updated October 05, 2023)
The master-station DNP3 driver before driver19.exe, and Beta2041.exe, in IOServer allows remote attackers to cause a denial of service (infinite loop) via crafted DNP3 packets to TCP port 20000.
0
Attacker Value
Unknown
CVE-2013-2783
Disclosure Date: June 14, 2013 (last updated October 05, 2023)
The DNP3 driver in IOServer drivers 1.0.19.0 allows remote attackers to cause a denial of service (infinite loop) or obtain unspecified control via crafted data to TCP port 20000.
0
Attacker Value
Unknown
CVE-2013-2279
Disclosure Date: March 21, 2013 (last updated October 05, 2023)
CA SiteMinder Federation (FSS) 12.5, 12.0, and r6; Federation (Standalone) 12.1 and 12.0; Agent for SharePoint 2010; and SiteMinder for Secure Proxy Server 6.0, 12.0, and 12.5 does not properly verify XML signatures for SAML statements, which allows remote attackers to spoof other users and gain privileges.
0
Attacker Value
Unknown
CVE-2012-5875
Disclosure Date: January 18, 2013 (last updated October 05, 2023)
Firefly Media Server 1.0.0.1359 allows remote attackers to cause a denial of service (NULL pointer dereference) via a (1) crafted Connection HTTP header; a return carriage control character in the (2) Accept Language header, (3) User-agent header, (4) Host header, or (5) protocol version; or a (6) crafted HTTP protocol version.
0
Attacker Value
Unknown
CVE-2012-4729
Disclosure Date: October 26, 2012 (last updated October 05, 2023)
Wing FTP Server before 4.1.1 allows remote authenticated users to cause a denial of service (daemon crash) via two zip commands.
0
Attacker Value
Unknown
CVE-2012-4680
Disclosure Date: August 27, 2012 (last updated October 05, 2023)
Directory traversal vulnerability in the XML Server in IOServer before 1.0.19.0, when the Root Directory pathname lacks a trailing \ (backslash) character, allows remote attackers to read arbitrary files or list arbitrary directories via a .. (dot dot) in a URI.
0
Attacker Value
Unknown
CVE-2012-1034
Disclosure Date: February 08, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the admin interface in EPiServer CMS through 6R2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-1031
Disclosure Date: February 08, 2012 (last updated October 04, 2023)
Unspecified vulnerability in EPiServer CMS 5 and 6 through 6R2, in certain configurations using Forms Authentication, allows remote authenticated users to obtain WebAdmins access by leveraging Edit Mode privileges, a different vulnerability than CVE-2011-3416 and CVE-2011-3417.
0