Show filters
76 Total Results
Displaying 51-60 of 76
Sort by:
Attacker Value
Unknown
CVE-2017-17982
Disclosure Date: December 30, 2017 (last updated November 26, 2024)
PHP Scripts Mall Muslim Matrimonial Script has CSRF via admin/subadmin_edit.php.
0
Attacker Value
Unknown
CVE-2017-17639
Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.
0
Attacker Value
Unknown
CVE-2017-7242
Disclosure Date: March 23, 2017 (last updated November 26, 2024)
Multiple Cross-Site Scripting (XSS) were discovered in admin/modules components in SLiMS 7 Cendana through 2017-03-23: the keywords parameter to bibliography/checkout_item.php, bibliography/dl_print.php, bibliography/item.php, bibliography/item_barcode_generator.php, bibliography/printed_card.php, circulation/loan_rules.php, master_file/author.php, master_file/coll_type.php, and master_file/doc_language.php and the quickReturnID field to circulation/ajax_action.php.
0
Attacker Value
Unknown
CVE-2017-7202
Disclosure Date: March 21, 2017 (last updated November 26, 2024)
Multiple Cross-Site Scripting (XSS) were discovered in SLiMS 7 Cendana before 2017-03-16. The vulnerabilities exist due to insufficient filtration of user-supplied data (id) passed to the 'slims7_cendana-master/template/default/detail_template.php' and 'slims7_cendana-master/template/default-rtl/detail_template.php' URLs. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
0
Attacker Value
Unknown
CVE-2016-8225
Disclosure Date: January 26, 2017 (last updated November 25, 2024)
Unquoted service path vulnerability in Lenovo Edge and Lenovo Slim USB Keyboard Driver versions earlier than 1.21 allows local users to execute code with elevated privileges.
0
Attacker Value
Unknown
CVE-2016-6257
Disclosure Date: August 02, 2016 (last updated November 25, 2024)
The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM600 and Ultraslim Wireless mice, does not enforce incrementing AES counters, which allows remote attackers to inject encrypted keyboard input into the system by leveraging proximity to the dongle, aka a "KeyJack injection attack."
0
Attacker Value
Unknown
CVE-2015-2171
Disclosure Date: March 30, 2015 (last updated October 05, 2023)
Middleware/SessionCookie.php in Slim before 2.6.0 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via crafted session data.
0
Attacker Value
Unknown
CVE-2015-1204
Disclosure Date: January 21, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Save Filters functionality in the WP Slimstat plugin before 3.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the fs[resource] parameter in the wp-slim-view-2 page to wp-admin/admin.php.
0
Attacker Value
Unknown
CVE-2014-100027
Disclosure Date: January 13, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the WP SlimStat plugin before 3.5.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
0
Attacker Value
Unknown
CVE-2014-7789
Disclosure Date: October 21, 2014 (last updated October 05, 2023)
The Zillion Muslims (aka com.zillionmuslims.src) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0