Show filters
116 Total Results
Displaying 61-70 of 116
Sort by:
Attacker Value
Unknown
CVE-2023-4117
Disclosure Date: August 03, 2023 (last updated October 08, 2023)
A vulnerability, which was classified as problematic, has been found in PHP Jabbers Rental Property Booking 2.0. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack may be launched remotely. The identifier of this vulnerability is VDB-235964. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2023-4110
Disclosure Date: August 03, 2023 (last updated October 08, 2023)
A vulnerability has been found in PHP Jabbers Availability Booking Calendar 5.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument session_id leads to cross site scripting. The attack can be launched remotely. The identifier VDB-235957 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2023-33564
Disclosure Date: August 01, 2023 (last updated October 08, 2023)
There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Time Slots Booking Calendar v3.3.
0
Attacker Value
Unknown
CVE-2023-33563
Disclosure Date: August 01, 2023 (last updated October 08, 2023)
In PHP Jabbers Time Slots Booking Calendar 3.3 , lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
0
Attacker Value
Unknown
CVE-2023-33562
Disclosure Date: August 01, 2023 (last updated October 08, 2023)
User enumeration is found in in PHP Jabbers Time Slots Booking Calendar v3.3. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
0
Attacker Value
Unknown
CVE-2023-33561
Disclosure Date: August 01, 2023 (last updated October 08, 2023)
Improper input validation of password parameter in PHP Jabbers Time Slots Booking Calendar v 3.3 results in insecure passwords.
0
Attacker Value
Unknown
CVE-2023-33560
Disclosure Date: August 01, 2023 (last updated October 08, 2023)
There is a Cross Site Scripting (XSS) vulnerability in "cid" parameter of preview.php in PHPJabbers Time Slots Booking Calendar v3.3.
0
Attacker Value
Unknown
CVE-2023-3970
Disclosure Date: July 27, 2023 (last updated October 08, 2023)
A vulnerability, which was classified as problematic, was found in GZ Scripts Availability Booking Calendar PHP 1.0. This affects an unknown part of the file /index.php?controller=GzUser&action=edit&id=1 of the component Image Handler. The manipulation of the argument img leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235569 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-3969
Disclosure Date: July 27, 2023 (last updated October 08, 2023)
A vulnerability, which was classified as problematic, has been found in GZ Scripts Availability Booking Calendar PHP 1.0. Affected by this issue is some unknown functionality of the file index.php of the component HTTP POST Request Handler. The manipulation of the argument promo_code leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-235568.
0
Attacker Value
Unknown
CVE-2023-36384
Disclosure Date: July 18, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodePeople Booking Calendar Contact Form plugin <= 1.2.40 versions.
0