Show filters
1,273 Total Results
Displaying 51-60 of 1,273
Sort by:
Attacker Value
Unknown
CVE-2024-12932
Disclosure Date: December 26, 2024 (last updated January 05, 2025)
A vulnerability was found in code-projects Simple Admin Panel 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file addSizeController.php. The manipulation of the argument size leads to cross site scripting. The attack can be launched remotely.
0
Attacker Value
Unknown
CVE-2024-12931
Disclosure Date: December 26, 2024 (last updated January 05, 2025)
A vulnerability was found in code-projects Simple Admin Panel 1.0. It has been classified as critical. Affected is an unknown function of the file /addCatController.php. The manipulation of the argument size leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-12930
Disclosure Date: December 26, 2024 (last updated January 05, 2025)
A vulnerability was found in code-projects Simple Admin Panel 1.0 and classified as problematic. This issue affects some unknown processing of the file addCatController.php. The manipulation of the argument c_name leads to cross site scripting. The attack may be initiated remotely.
0
Attacker Value
Unknown
CVE-2024-12928
Disclosure Date: December 26, 2024 (last updated January 05, 2025)
A vulnerability, which was classified as critical, was found in code-projects Simple Admin Panel 1.0. This affects an unknown part. The manipulation of the argument c_name leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-11722
Disclosure Date: December 21, 2024 (last updated December 21, 2024)
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.25.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This requires an unauthenticated user to have been given permission to view form submissions, and the form submission shortcode be added to a page.
0
Attacker Value
Unknown
CVE-2024-10385
Disclosure Date: December 20, 2024 (last updated December 21, 2024)
Ticket management system in DirectAdmin Evolution Skin is vulnerable to XSS (Cross-site Scripting), which allows a low-privileged user to inject and store malicious JavaScript code.
If an admin views the ticket, the script might perform actions with their privileges, including command execution.
This issue has been fixed in version 1.668 of DirectAdmin Evolution Skin.
0
Attacker Value
Unknown
CVE-2024-9102
Disclosure Date: December 19, 2024 (last updated December 20, 2024)
phpLDAPadmin since at least version 1.2.0 through the latest version 1.2.6.7 allows users to export elements from the LDAP directory into a Comma-Separated Value (CSV) file, but it does not neutralize special elements that could be interpreted as a command when the file is opened by a spreadsheet product. Thus, this could lead to CSV Formula Injection.
0
Attacker Value
Unknown
CVE-2024-9101
Disclosure Date: December 19, 2024 (last updated December 20, 2024)
A reflected cross-site scripting (XSS) vulnerability in the 'Entry Chooser' of phpLDAPadmin (version 1.2.1 through the latest version, 1.2.6.7) allows attackers to execute arbitrary JavaScript in the user's browser via the 'element' parameter, which is unsafely passed to the JavaScript 'eval' function. However, exploitation is limited to specific conditions where 'opener' is correctly set.
0
Attacker Value
Unknown
CVE-2024-55864
Disclosure Date: December 17, 2024 (last updated December 18, 2024)
Cross-site scripting vulnerability exists in My WP Customize Admin/Frontend versions prior to ver 1.24.1. If a malicious administrative user customizes the administrative page with some malicious contents, an arbitrary script may be executed on the web browser of the other users who are accessing the page.
0
Attacker Value
Unknown
CVE-2024-12663
Disclosure Date: December 16, 2024 (last updated December 18, 2024)
A vulnerability classified as problematic was found in funnyzpc Mee-Admin up to 1.6. This vulnerability affects unknown code of the file /mee/login of the component Login. The manipulation of the argument username leads to observable response discrepancy. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.
0