Show filters
77 Total Results
Displaying 51-60 of 77
Sort by:
Attacker Value
Unknown

CVE-2019-17237

Disclosure Date: November 12, 2019 (last updated November 27, 2024)
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF.
Attacker Value
Unknown

CVE-2019-17235

Disclosure Date: November 12, 2019 (last updated November 27, 2024)
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows information disclosure.
Attacker Value
Unknown

CVE-2019-13370

Disclosure Date: July 06, 2019 (last updated February 17, 2024)
index.php/admin/permissions in Ignited CMS through 2017-02-19 allows CSRF to add an administrator.
Attacker Value
Unknown

CVE-2015-3907

Disclosure Date: July 03, 2019 (last updated November 27, 2024)
CodeIgniter Rest Server (aka codeigniter-restserver) 2.7.1 allows XXE attacks.
0
Attacker Value
Unknown

CVE-2018-15203

Disclosure Date: August 08, 2018 (last updated February 17, 2024)
An issue was discovered in Ignited CMS through 2017-02-19. ign/index.php/admin/pages/add_page allows a CSRF attack to add pages.
Attacker Value
Unknown

CVE-2018-8018

Disclosure Date: July 20, 2018 (last updated November 08, 2023)
In Apache Ignite before 2.4.8 and 2.5.x before 2.5.3, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary code when 3-rd party vulnerable classes are present in Ignite classpath. The vulnerability can be exploited if the one sends a specially prepared form of a serialized object to GridClientJdkMarshaller deserialization endpoint.
0
Attacker Value
Unknown

CVE-2018-12071

Disclosure Date: June 17, 2018 (last updated November 26, 2024)
A Session Fixation issue exists in CodeIgniter before 3.1.9 because session.use_strict_mode in the Session Library was mishandled.
0
Attacker Value
Unknown

CVE-2016-10552

Disclosure Date: May 31, 2018 (last updated November 26, 2024)
igniteui 0.0.5 and earlier downloads JavaScript and CSS resources over insecure protocol.
0
Attacker Value
Unknown

CVE-2018-1273

Disclosure Date: April 11, 2018 (last updated July 17, 2024)
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.
Attacker Value
Unknown

CVE-2018-1295

Disclosure Date: April 02, 2018 (last updated November 08, 2023)
In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary code when 3-rd party vulnerable classes are present in Ignite classpath. The vulnerability can be exploited if the one sends a specially prepared form of a serialized object to one of the deserialization endpoints of some Ignite components - discovery SPI, Ignite persistence, Memcached endpoint, socket steamer.
0