Show filters
95 Total Results
Displaying 51-60 of 95
Sort by:
Attacker Value
Unknown

CVE-2013-4754

Disclosure Date: December 26, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Owl Intranet Knowledgebase 1.10 allow remote authenticated users to inject arbitrary web script or HTML via (1) the Search field to browse.php or (2) the Title field to prefs.php.
0
Attacker Value
Unknown

CVE-2014-7692

Disclosure Date: October 21, 2014 (last updated October 05, 2023)
The Lent Experience (aka com.wLentExperience) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-6864

Disclosure Date: October 02, 2014 (last updated October 05, 2023)
The Forest River Forums (aka com.socialknowledge.forestriverforums) application 3.7.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-5973

Disclosure Date: September 20, 2014 (last updated October 05, 2023)
The Aquarium Advice (aka com.socialknowledge.aquariumadvice) application 3.7.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-2737

Disclosure Date: April 22, 2014 (last updated October 05, 2023)
SQL injection vulnerability in the get_active_session function in the KTAPI_UserSession class in webservice/clienttools/services/mdownload.php in KnowledgeTree 3.7.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the u parameter, related to the getFileName function.
0
Attacker Value
Unknown

CVE-2013-3616

Disclosure Date: September 24, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the KnowledgeView Editorial and Management application allows remote attackers to inject arbitrary web script or HTML via the username parameter.
0
Attacker Value
Unknown

CVE-2011-5195

Disclosure Date: September 23, 2012 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Conference Systems 2.3.4 and earlier allows remote attackers to hijack the authentication of administrators for requests that upload a PHP file.
0
Attacker Value
Unknown

CVE-2011-5197

Disclosure Date: September 23, 2012 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Harvester Systems 2.3.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that upload PHP files.
0
Attacker Value
Unknown

CVE-2011-5196

Disclosure Date: September 23, 2012 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Journal Systems 2.3.6 and earlier allows remote attackers to hijack the authentication of administrators for requests that upload PHP files.
0
Attacker Value
Unknown

CVE-2012-2728

Disclosure Date: June 27, 2012 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in the Node Hierarchy module 6.x-1.x before 6.x-1.5 for Drupal allow remote attackers to hijack the authentication of administrators for requests that change a node hierarchy position via an (1) up or (2) down action.
0