Show filters
109 Total Results
Displaying 61-70 of 109
Sort by:
Attacker Value
Unknown

CVE-2018-16157

Disclosure Date: August 30, 2018 (last updated November 27, 2024)
waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing data in a packet capture. By setting the index.php?m=cart&a=save item_totals parameter to zero, the entire cart is sold for free.
0
Attacker Value
Unknown

CVE-2018-15570

Disclosure Date: August 20, 2018 (last updated November 27, 2024)
In waimai Super Cms 20150505, there is stored XSS via the /admin.php/Foodcat/editsave fcname parameter.
0
Attacker Value
Unknown

CVE-2018-7316

Disclosure Date: February 22, 2018 (last updated November 26, 2024)
Arbitrary File Upload exists in the Proclaim 9.1.1 component for Joomla! via a mediafileform action.
0
Attacker Value
Unknown

CVE-2018-7317

Disclosure Date: February 22, 2018 (last updated November 26, 2024)
Backup Download exists in the Proclaim 9.1.1 component for Joomla! via a direct request for a .sql file under backup/.
0
Attacker Value
Unknown

CVE-2012-5816

Disclosure Date: November 04, 2012 (last updated October 05, 2023)
AOL Instant Messenger (AIM) 1.0.1.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
0
Attacker Value
Unknown

CVE-2011-4214

Disclosure Date: November 01, 2011 (last updated October 04, 2023)
OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to bypass authentication and obtain administrator privileges via a crafted oozimsrememberme cookie.
0
Attacker Value
Unknown

CVE-2011-4215

Disclosure Date: November 01, 2011 (last updated October 04, 2023)
SQL injection vulnerability in lib/ooz_access.php in OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to execute arbitrary SQL commands via the cookieName variable.
0
Attacker Value
Unknown

CVE-2010-4835

Disclosure Date: September 14, 2011 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in OneOrZero AIMS 2.6.0 Members Edition allows remote authenticated users to read arbitrary files via directory traversal sequences in the controller parameter in a show_report action.
0
Attacker Value
Unknown

CVE-2010-4834

Disclosure Date: September 14, 2011 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in index.php in OneOrZero AIMS 2.6.0 Members Edition and 2.7.0 Trial Edition allow remote authenticated users to execute arbitrary SQL commands via the (1) id parameter in a saved_search action and (2) item_types parameter in a show_item_search action in the search_management_manage subcontroller. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2010-2034

Disclosure Date: May 25, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in the Percha Image Attach (com_perchaimageattach) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
0