Show filters
64 Total Results
Displaying 51-60 of 64
Sort by:
Attacker Value
Unknown
CVE-2019-0708
Disclosure Date: May 16, 2019 (last updated July 26, 2024)
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
0
Attacker Value
Unknown
CVE-2019-11886
Disclosure Date: May 13, 2019 (last updated November 27, 2024)
The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as demonstrated by use of yp_remote_get to obtain admin access.
0
Attacker Value
Unknown
CVE-2016-10548
Disclosure Date: May 31, 2018 (last updated November 26, 2024)
Arbitrary code execution is possible in reduce-css-calc node module <=1.2.4 through crafted css. This makes cross sites scripting (XSS) possible on the client and arbitrary code injection possible on the server and user input is passed to the `calc` function.
0
Attacker Value
Unknown
CVE-2018-1000108
Disclosure Date: March 13, 2018 (last updated November 26, 2024)
A cross-site scripting vulnerability exists in Jenkins CppNCSS Plugin 1.1 and earlier in AbstractProjectAction/index.jelly that allow an attacker to craft links to Jenkins URLs that run arbitrary JavaScript in the user's browser when accessed.
0
Attacker Value
Unknown
CVE-2017-2285
Disclosure Date: August 02, 2017 (last updated November 26, 2024)
Cross-site scripting vulnerability in Simple Custom CSS and JS prior to version 3.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-5570
Disclosure Date: August 23, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Javascript and CSS Optimizer extension before 1.1.14 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-0206
Disclosure Date: March 19, 2013 (last updated October 05, 2023)
Unrestricted file upload vulnerability in the Live CSS module 6.x-2.x before 6.x-2.1 and 7.x-2.x before 7.x-2.7 for Drupal allows remote authenticated users with the "administer CSS" permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.
0
Attacker Value
Unknown
CVE-2011-4713
Disclosure Date: December 08, 2011 (last updated October 04, 2023)
Directory traversal vulnerability in catalog/content.php in osCSS2 2.1.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the _ID parameter to (1) catalog/shopping_cart.php or (2) catalog/content.php.
0
Attacker Value
Unknown
CVE-2010-2856
Disclosure Date: July 25, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in admin/currencies.php in osCSS 1.2.2, and probably earlier versions, allows remote attackers to inject arbitrary web script or HTML via the page parameter.
0
Attacker Value
Unknown
CVE-2009-3284
Disclosure Date: September 22, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in phpspot PHP BBS, PHP Image Capture BBS, PHP & CSS BBS, PHP BBS CE, PHP_RSS_Builder, and webshot, dated before 20090914, allows remote attackers to read arbitrary files via unspecified vectors.
0