Show filters
74 Total Results
Displaying 51-60 of 74
Sort by:
Attacker Value
Unknown
CVE-2021-24800
Disclosure Date: April 25, 2022 (last updated February 23, 2025)
The DW Question & Answer Pro WordPress plugin through 1.3.4 does not check that the comment to edit belongs to the user making the request, allowing any user to edit other comments.
0
Attacker Value
Unknown
CVE-2019-16251
Disclosure Date: October 31, 2019 (last updated November 27, 2024)
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
0
Attacker Value
Unknown
CVE-2017-15725
Disclosure Date: October 28, 2019 (last updated November 27, 2024)
An XML External Entity Injection vulnerability exists in Dzone AnswerHub.
0
Attacker Value
Unknown
CVE-2017-17871
Disclosure Date: December 27, 2017 (last updated November 26, 2024)
The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter.
0
Attacker Value
Unknown
CVE-2017-12775
Disclosure Date: August 29, 2017 (last updated November 26, 2024)
qa-include/qa-install.php in Question2Answer before 1.7.5 allows remote attackers to create multiple user accounts.
0
Attacker Value
Unknown
CVE-2012-4257
Disclosure Date: August 13, 2012 (last updated October 04, 2023)
Yaqas (Yet Another Question & Answer System) 1.0 Alpha 1 allows remote attackers to obtain sensitive information via an invalid character in the PHPSESSID, which reveals the installation path in an error message.
0
Attacker Value
Unknown
CVE-2009-4868
Disclosure Date: May 11, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Hitron Soft Answer Me 1.0 allows remote attackers to inject arbitrary web script or HTML via the q_id parameter to the answers script (aka answers.php). NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2009-4858
Disclosure Date: May 11, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in questiondetail.php in Yahoo Answers Clone allows remote attackers to inject arbitrary web script or HTML via the questionid parameter.
0
Attacker Value
Unknown
CVE-2009-4728
Disclosure Date: March 18, 2010 (last updated October 04, 2023)
SQL injection vulnerability in the administrative interface in Questions Answered 1.3 allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2009-1665
Disclosure Date: May 18, 2009 (last updated October 04, 2023)
myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to remove arbitrary user accounts via a modified userid parameter without specifying any additional fields.
0