Show filters
83 Total Results
Displaying 51-60 of 83
Sort by:
Attacker Value
Unknown

CVE-2018-19793

Disclosure Date: December 03, 2018 (last updated November 27, 2024)
jiacrontab 1.4.5 allows remote attackers to execute arbitrary commands via the crontab/task/edit?addr=localhost%3a20001 command and args parameters, as demonstrated by command=cat&args=/etc/passwd in the POST data.
0
Attacker Value
Unknown

CVE-2017-14530

Disclosure Date: September 18, 2017 (last updated November 26, 2024)
WP_Admin_UI in the Crony Cronjob Manager plugin before 0.4.7 for WordPress has CSRF via the name parameter in an action=manage&do=create operation, as demonstrated by inserting XSS sequences.
Attacker Value
Unknown

CVE-2017-9525

Disclosure Date: June 09, 2017 (last updated November 26, 2024)
In the cron package through 3.0pl1-128 on Debian, and through 3.0pl1-128ubuntu2 on Ubuntu, the postinst maintainer script allows for group-crontab-to-root privilege escalation via symlink attacks against unsafe usage of the chown and chmod programs.
Attacker Value
Unknown

CVE-2016-3992

Disclosure Date: July 26, 2016 (last updated November 25, 2024)
cronic before 3 allows local users to write to arbitrary files via a symlink attack on a (1) cronic.out.$$, (2) cronic.err.$$, or (3) cronic.trace.$$ file in /tmp.
0
Attacker Value
Unknown

CVE-2014-10032

Disclosure Date: January 13, 2015 (last updated October 05, 2023)
SQL injection vulnerability in news_popup.php in Taboada MacroNews 1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2012-6110

Disclosure Date: September 29, 2014 (last updated October 05, 2023)
bcron-exec in bcron before 0.10 does not close file descriptors associated with temporary files when running a cron job, which allows local users to modify job files and send spam messages by accessing an open file descriptor.
0
Attacker Value
Unknown

CVE-2013-6991

Disclosure Date: January 03, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the WP-Cron Dashboard plugin 1.1.5 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the procname parameter to wp-admin/tools.php.
0
Attacker Value
Unknown

CVE-2012-6097

Disclosure Date: April 09, 2013 (last updated October 05, 2023)
File descriptor leak in cronie 1.4.8, when running in certain environments, might allow local users to read restricted files, as demonstrated by reading /etc/crontab.
0
Attacker Value
Unknown

CVE-2012-1628

Disclosure Date: September 20, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the SuperCron module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2010-0792

Disclosure Date: March 05, 2010 (last updated October 04, 2023)
fcrontab in fcron before 3.0.5 allows local users to read arbitrary files via a symlink attack on an unspecified file.
0