Show filters
75 Total Results
Displaying 51-60 of 75
Sort by:
Attacker Value
Unknown

CVE-2016-10038

Disclosure Date: December 24, 2016 (last updated November 25, 2024)
Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/remove.
0
Attacker Value
Unknown

CVE-2010-5310

Disclosure Date: August 04, 2015 (last updated October 05, 2023)
The Acquisition Workstation for the GE Healthcare Revolution XQ/i has a password of adw3.1 for the sdc user, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.
0
Attacker Value
Unknown

CVE-2014-9734

Disclosure Date: June 30, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in the Slider Revolution (revslider) plugin before 4.2 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin/admin-ajax.php.
0
Attacker Value
Unknown

CVE-2015-5151

Disclosure Date: June 30, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Slider Revolution (revslider) plugin 4.2.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the client_action parameter in a revslider_ajax_action action to wp-admin/admin-ajax.php.
0
Attacker Value
Unknown

CVE-2014-9735

Disclosure Date: June 30, 2015 (last updated October 05, 2023)
The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier for Wordpress does not properly restrict access to administrator AJAX functionality, which allows remote attackers to (1) upload and execute arbitrary files via an update_plugin action; (2) delete arbitrary sliders via a delete_slider action; and (3) create, (4) update, (5) import, or (6) export arbitrary sliders via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-1400

Disclosure Date: February 03, 2015 (last updated October 05, 2023)
SQL injection vulnerability in search.php in NPDS Revolution 13 allows remote attackers to execute arbitrary SQL commands via the query parameter.
0
Attacker Value
Unknown

CVE-2014-8992

Disclosure Date: December 22, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in manager/assets/fileapi/FileAPI.flash.image.swf in MODX Revolution 2.3.2-pl allows remote attackers to inject arbitrary web script or HTML via the callback parameter.
0
Attacker Value
Unknown

CVE-2014-8774

Disclosure Date: December 03, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in manager/index.php in MODX Revolution 2.x before 2.2.15 allows remote attackers to inject arbitrary web script or HTML via the context_key parameter.
0
Attacker Value
Unknown

CVE-2014-8775

Disclosure Date: December 03, 2014 (last updated October 05, 2023)
MODX Revolution 2.x before 2.2.15 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
0
Attacker Value
Unknown

CVE-2014-8773

Disclosure Date: December 03, 2014 (last updated October 05, 2023)
MODX Revolution 2.x before 2.2.15 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism by (1) omitting the CSRF token or via a (2) long string in the CSRF token parameter.
0