Show filters
82 Total Results
Displaying 51-60 of 82
Sort by:
Attacker Value
Unknown
CVE-2019-12566
Disclosure Date: June 03, 2019 (last updated November 27, 2024)
The WP Statistics plugin through 12.6.5 for Wordpress has stored XSS in includes/class-wp-statistics-pages.php. This is related to an account with the Editor role creating a post with a title that contains JavaScript, to attack an admin user.
0
Attacker Value
Unknown
TIBCO Spotfire Statistics Services Exposes Sensitive Files
Disclosure Date: May 14, 2019 (last updated November 27, 2024)
The web interface component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that might theoretically allow an authenticated user to access sensitive information needed by the Spotfire Statistics Services server. The sensitive information that might be affected includes database, JMX, LDAP, Windows service account, and user credentials. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Statistics Services: versions up to and including 7.11.1; 10.0.0.
0
Attacker Value
Unknown
CVE-2019-10864
Disclosure Date: April 23, 2019 (last updated November 08, 2023)
The WP Statistics plugin through 12.6.2 for WordPress has XSS, allowing a remote attacker to inject arbitrary web script or HTML via the Referer header of a GET request.
0
Attacker Value
Unknown
TIBCO Spotfire Statistics Services remote execution vulnerabilities
Disclosure Date: October 10, 2018 (last updated November 27, 2024)
The web server component of TIBCO Software Inc's Spotfire Statistics Services contains multiple vulnerabilities that may allow the remote execution of code. Without needing to authenticate, an attacker may be able to remotely execute code with the permissions of the system account used to run the web server component. Affected releases are TIBCO Software Inc. TIBCO Spotfire Statistics Services versions up to and including 7.11.0.
0
Attacker Value
Unknown
CVE-2018-17074
Disclosure Date: September 16, 2018 (last updated November 27, 2024)
The Feed Statistics plugin before 4.0 for WordPress has an Open Redirect via the feed-stats-url parameter.
0
Attacker Value
Unknown
CVE-2018-1000556
Disclosure Date: June 26, 2018 (last updated November 26, 2024)
WordPress version 4.8 + contains a Cross Site Scripting (XSS) vulnerability in plugins.php or core wordpress on delete function that can result in An attacker can perform client side attacks which could be from stealing a cookie to code injection. This attack appear to be exploitable via an attacker must craft an URL with payload and send to the user. Victim need to open the link to be affected by reflected XSS. .
0
Attacker Value
Unknown
CVE-2018-11532
Disclosure Date: May 29, 2018 (last updated November 26, 2024)
An issue was discovered in the ChangUonDyU Advanced Statistics plugin 1.0.2 for MyBB. changstats.php has XSS, as demonstrated by a subject field.
0
Attacker Value
Unknown
CVE-2017-10991
Disclosure Date: July 07, 2017 (last updated November 08, 2023)
The WP Statistics plugin through 12.0.9 for WordPress has XSS in the rangestart and rangeend parameters on the wps_referrers_page page.
0
Attacker Value
Unknown
CVE-2017-2136
Disclosure Date: April 28, 2017 (last updated November 26, 2024)
Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers.
0
Attacker Value
Unknown
CVE-2017-2135
Disclosure Date: April 28, 2017 (last updated November 26, 2024)
Cross-site scripting vulnerability in WP Statistics version 12.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0