Show filters
284 Total Results
Displaying 61-70 of 284
Sort by:
Attacker Value
Unknown
CVE-2023-51062
Disclosure Date: January 13, 2024 (last updated January 20, 2024)
An unauthenticated log file read in the component log-smblog-save of QStar Archive Solutions RELEASE_3-0 Build 7 Patch 0 allows attackers to disclose the SMB Log contents via executing a crafted command.
0
Attacker Value
Unknown
CVE-2023-49847
Disclosure Date: December 14, 2023 (last updated December 19, 2023)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Twinpictures Annual Archive allows Stored XSS.This issue affects Annual Archive: from n/a through 1.6.0.
0
Attacker Value
Unknown
CVE-2023-46194
Disclosure Date: October 27, 2023 (last updated February 25, 2025)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.5 versions.
0
Attacker Value
Unknown
CVE-2023-46069
Disclosure Date: October 25, 2023 (last updated February 25, 2025)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Osmansorkar Ajax Archive Calendar plugin <= 2.6.7 versions.
0
Attacker Value
Unknown
CVE-2023-45815
Disclosure Date: October 19, 2023 (last updated February 25, 2025)
ArchiveBox is an open source self-hosted web archiving system. Any users who are using the `wget` extractor and view the content it outputs. The impact is potentially severe if you are logged in to the ArchiveBox admin site in the same browser session and view an archived malicious page designed to target your ArchiveBox instance. Malicious Javascript could potentially act using your logged-in admin credentials and add/remove/modify snapshots, add/remove/modify ArchiveBox users, and generally do anything an admin user could do. The impact is less severe for non-logged-in users, as malicious Javascript cannot *modify* any archives, but it can still *read* all the other archived content by fetching the snapshot index and iterating through it. Because all of ArchiveBox's archived content is served from the same host and port as the admin panel, when archived pages are viewed the JS executes in the same context as all the other archived pages (and the admin panel), defeating most of the b…
0
Attacker Value
Unknown
CVE-2023-39069
Disclosure Date: September 11, 2023 (last updated February 25, 2025)
An issue in StrangeBee TheHive v.5.0.8, v.4.1.21 and Cortex v.3.1.6 allows a remote attacker to gain privileges via Active Directory authentication mechanism.
0
Attacker Value
Unknown
CVE-2023-39139
Disclosure Date: August 30, 2023 (last updated February 25, 2025)
An issue in Archive v3.3.7 allows attackers to execute a path traversal via extracting a crafted zip file.
0
Attacker Value
Unknown
CVE-2023-39137
Disclosure Date: August 30, 2023 (last updated February 25, 2025)
An issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing.
0
Attacker Value
Unknown
CVE-2023-39136
Disclosure Date: August 30, 2023 (last updated February 25, 2025)
An unhandled edge case in the component _sanitizedPath of ZipArchive v2.5.4 allows attackers to cause a Denial of Service (DoS) via a crafted zip file.
0
Attacker Value
Unknown
CVE-2023-3136
Disclosure Date: August 30, 2023 (last updated October 08, 2023)
The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 2.10.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0