Show filters
115 Total Results
Displaying 61-70 of 115
Sort by:
Attacker Value
Unknown

CVE-2021-24574

Disclosure Date: August 23, 2021 (last updated February 23, 2025)
The Simple Banner WordPress plugin before 2.10.4 does not sanitise and escape one of its settings, allowing high privilege users such as admin to use Cross-Site Scripting payload even when the unfiltered_html capability is disallowed.
Attacker Value
Unknown

CVE-2021-24252

Disclosure Date: May 06, 2021 (last updated February 22, 2025)
The Event Banner WordPress plugin through 1.3 does not verify the uploaded image file, allowing admin accounts to upload arbitrary files, such as .exe, .php, or others executable, leading to RCE. Due to the lack of CSRF check, the issue can also be used via such vector to achieve the same result, or via a LFI as authorisation checks are missing (but would require WP to be loaded)
Attacker Value
Unknown

CVE-2019-8978

Disclosure Date: May 14, 2019 (last updated November 27, 2024)
An improper authentication vulnerability can be exploited through a race condition that occurs in Ellucian Banner Web Tailor 8.8.3, 8.8.4, and 8.9 and Banner Enterprise Identity Services 8.3, 8.3.1, 8.3.2, and 8.4, in conjunction with SSO Manager. This vulnerability allows remote attackers to steal a victim's session (and cause a denial of service) by repeatedly requesting the initial Banner Web Tailor main page with the IDMSESSID cookie set to the victim's UDCID, which in the case tested is the institutional ID. During a login attempt by a victim, the attacker can leverage the race condition and will be issued the SESSID that was meant for this victim.
0
Attacker Value
Unknown

CVE-2018-11579

Disclosure Date: May 31, 2018 (last updated November 26, 2024)
class-woo-banner-management.php in the MULTIDOTS WooCommerce Category Banner Management plugin 1.1.0 for WordPress has an Unauthenticated Settings Change Vulnerability, related to certain wp_ajax_nopriv_ usage. Anyone can change the plugin's setting by simply sending a request with a wbm_save_shop_page_banner_data action.
0
Attacker Value
Unknown

CVE-2015-4689

Disclosure Date: September 11, 2017 (last updated November 26, 2024)
Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to reset arbitrary passwords via unspecified vectors, aka "Weak Password Reset."
0
Attacker Value
Unknown

CVE-2015-4687

Disclosure Date: September 11, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Ellucian (formerly SunGard) Banner Student 8.5.1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-5054

Disclosure Date: September 11, 2017 (last updated November 26, 2024)
Open redirect vulnerability in Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in an unspecified parameter.
0
Attacker Value
Unknown

CVE-2015-4688

Disclosure Date: September 11, 2017 (last updated November 26, 2024)
Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allow remote attackers to enumerate user accounts via a series of requests.
0
Attacker Value
Unknown

CVE-2015-1384

Disclosure Date: February 03, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Banner Effect Header plugin before 1.2.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via the banner_effect_divid parameter in the BannerEffectOptions page to wp-admin/options-general.php.
0
Attacker Value
Unknown

CVE-2015-0920

Disclosure Date: January 08, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the Banner Effect Header plugin 1.2.6 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the banner_effect_email parameter in the BannerEffectOptions page to wp-admin/options-general.php.
0