Show filters
67 Total Results
Displaying 51-60 of 67
Sort by:
Attacker Value
Unknown
CVE-2019-1010266
Disclosure Date: July 17, 2019 (last updated November 27, 2024)
lodash prior to 4.17.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.17.11.
0
Attacker Value
Unknown
CVE-2019-12530
Disclosure Date: June 02, 2019 (last updated November 27, 2024)
Incorrect access control was discovered in the stdonato Dashboard plugin through 0.9.7 for GLPI, affecting df.php, issue.php, load.php, mem.php, traf.php, and uptime.php in front/sh.
0
Attacker Value
Unknown
CVE-2018-16487
Disclosure Date: February 01, 2019 (last updated November 27, 2024)
A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep can be tricked into adding or modifying properties of Object.prototype.
0
Attacker Value
Unknown
CVE-2018-3721
Disclosure Date: June 07, 2018 (last updated February 17, 2024)
lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
0
Attacker Value
Unknown
CVE-2016-10551
Disclosure Date: May 29, 2018 (last updated November 26, 2024)
waterline-sequel is a module that helps generate SQL statements for Waterline apps Any user input that goes into Waterline's `like`, `contains`, `startsWith`, or `endsWith` will end up in waterline-sequel with the potential for malicious code. A malicious user can input their own SQL statements in waterline-sequel 0.50 that will get executed and have full access to the database.
0
Attacker Value
Unknown
CVE-2018-7209
Disclosure Date: February 18, 2018 (last updated November 26, 2024)
An issue was discovered in iDashboards 9.6b. It allows remote attackers to obtain sensitive information via a direct request for the idashboards/config.xml URI, as demonstrated by intranet URLs for reports.
0
Attacker Value
Unknown
CVE-2018-7210
Disclosure Date: February 18, 2018 (last updated November 26, 2024)
An issue was discovered in iDashboards 9.6b. It allows remote attackers to obtain sensitive information via a direct request for the idb/config?CMD=installLicense URI, as demonstrated by intranet IP addresses and names of guest accounts.
0
Attacker Value
Unknown
CVE-2018-7211
Disclosure Date: February 18, 2018 (last updated November 26, 2024)
An issue was discovered in iDashboards 9.6b. The SSO implementation is affected by a weak obfuscation library, allowing man-in-the-middle attackers to discover credentials.
0
Attacker Value
Unknown
CVE-2017-1000473
Disclosure Date: January 03, 2018 (last updated November 26, 2024)
Linux Dash up to version v2 is vulnerable to multiple command injection vulnerabilities in the way module names are parsed and then executed resulting in code execution on the server, potentially as root.
0
Attacker Value
Unknown
CVE-2015-7877
Disclosure Date: September 11, 2017 (last updated November 26, 2024)
Multiple SQL injection vulnerabilities in the User Dashboard module 7.x before 7.x-1.4 for Drupal allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
0