Show filters
250 Total Results
Displaying 51-60 of 250
Sort by:
Attacker Value
Unknown
CVE-2022-4817
Disclosure Date: December 28, 2022 (last updated February 24, 2025)
A vulnerability was found in centic9 jgit-cookbook. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to insecure temporary file. The attack can be initiated remotely. The name of the patch is b8cb29b43dc704708d598c60ac1881db7cf8e9c3. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-216988.
0
Attacker Value
Unknown
CVE-2022-45290
Disclosure Date: December 09, 2022 (last updated February 24, 2025)
Kbase Doc v1.0 was discovered to contain an arbitrary file deletion vulnerability via the component /web/IndexController.java.
0
Attacker Value
Unknown
CVE-2022-40968
Disclosure Date: December 04, 2022 (last updated February 24, 2025)
Reflected Cross-Site Scripting (XSS) vulnerability in 2kb Amazon Affiliates Store plugin <=2.1.5 on WordPress.
0
Attacker Value
Unknown
CVE-2022-3137
Disclosure Date: October 10, 2022 (last updated February 24, 2025)
The Taskbuilder WordPress plugin before 1.0.8 does not validate and sanitise task's attachments, which could allow any authenticated user (such as subscriber) creating a task to perform Stored Cross-Site Scripting by attaching a malicious SVG file
0
Attacker Value
Unknown
CVE-2022-39196
Disclosure Date: September 05, 2022 (last updated May 07, 2024)
Blackboard Learn 1.10.1 allows remote authenticated users to read unintended files by entering student credentials and then directly visiting a certain webapps/bbcms/execute/ URL. Note: The vendor disputes this stating this cannot be reproduced.
0
Attacker Value
Unknown
CVE-2022-31158
Disclosure Date: July 15, 2022 (last updated February 24, 2025)
LTI 1.3 Tool Library is a library used for building IMS-certified LTI 1.3 tool providers in PHP. Prior to version 5.0, the Nonce Claim Value was not being validated against the nonce value sent in the Authentication Request. Users should upgrade to version 5.0 to receive a patch. There are currently no known workarounds.
0
Attacker Value
Unknown
CVE-2022-31157
Disclosure Date: July 15, 2022 (last updated February 24, 2025)
LTI 1.3 Tool Library is a library used for building IMS-certified LTI 1.3 tool providers in PHP. Prior to version 5.0, the function used to generate random nonces was not sufficiently cryptographically complex. Users should upgrade to version 5.0 to receive a patch. There are currently no known workarounds.
0
Attacker Value
Unknown
CVE-2017-20128
Disclosure Date: July 13, 2022 (last updated February 24, 2025)
A vulnerability has been found in KB Messages PHP Script 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument username/password with the input 'or''=' leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2017-20127
Disclosure Date: July 13, 2022 (last updated February 24, 2025)
A vulnerability was found in KB Login Authentication Script 1.1 and classified as critical. Affected by this issue is some unknown functionality. The manipulation of the argument username/password with the input 'or''=' leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2017-20126
Disclosure Date: July 13, 2022 (last updated February 24, 2025)
A vulnerability was found in KB Affiliate Referral Script 1.0. It has been classified as critical. This affects an unknown part of the file /index.php. The manipulation of the argument username/password with the input 'or''=' leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
0