Show filters
74 Total Results
Displaying 51-60 of 74
Sort by:
Attacker Value
Unknown

CVE-2021-24800

Disclosure Date: April 25, 2022 (last updated February 23, 2025)
The DW Question & Answer Pro WordPress plugin through 1.3.4 does not check that the comment to edit belongs to the user making the request, allowing any user to edit other comments.
Attacker Value
Unknown

CVE-2019-16251

Disclosure Date: October 31, 2019 (last updated November 27, 2024)
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
Attacker Value
Unknown

CVE-2017-15725

Disclosure Date: October 28, 2019 (last updated November 27, 2024)
An XML External Entity Injection vulnerability exists in Dzone AnswerHub.
Attacker Value
Unknown

CVE-2017-17871

Disclosure Date: December 27, 2017 (last updated November 26, 2024)
The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter.
0
Attacker Value
Unknown

CVE-2017-12775

Disclosure Date: August 29, 2017 (last updated November 26, 2024)
qa-include/qa-install.php in Question2Answer before 1.7.5 allows remote attackers to create multiple user accounts.
0
Attacker Value
Unknown

CVE-2012-4257

Disclosure Date: August 13, 2012 (last updated October 04, 2023)
Yaqas (Yet Another Question & Answer System) 1.0 Alpha 1 allows remote attackers to obtain sensitive information via an invalid character in the PHPSESSID, which reveals the installation path in an error message.
0
Attacker Value
Unknown

CVE-2009-4868

Disclosure Date: May 11, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Hitron Soft Answer Me 1.0 allows remote attackers to inject arbitrary web script or HTML via the q_id parameter to the answers script (aka answers.php). NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2009-4858

Disclosure Date: May 11, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in questiondetail.php in Yahoo Answers Clone allows remote attackers to inject arbitrary web script or HTML via the questionid parameter.
0
Attacker Value
Unknown

CVE-2009-4728

Disclosure Date: March 18, 2010 (last updated October 04, 2023)
SQL injection vulnerability in the administrative interface in Questions Answered 1.3 allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2009-1665

Disclosure Date: May 18, 2009 (last updated October 04, 2023)
myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to remove arbitrary user accounts via a modified userid parameter without specifying any additional fields.
0