Show filters
97 Total Results
Displaying 61-70 of 97
Sort by:
Attacker Value
Unknown

CVE-2017-17581

Disclosure Date: December 13, 2017 (last updated November 26, 2024)
FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter.
Attacker Value
Unknown

CVE-2015-3939

Disclosure Date: May 31, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in the NC854 and NC856 modules for IDS RTU 850C devices allows remote authenticated users to read arbitrary files via unspecified vectors involving an internal web server, as demonstrated by reading a TELNET credentials file.
0
Attacker Value
Unknown

CVE-2014-7376

Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The Facebook Profits on Steroids (aka com.wFacebookProfitsonSteroids) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-7021

Disclosure Date: October 16, 2014 (last updated October 05, 2023)
The Leg Surgery - Kids Games (aka com.harriskerioe.legsurgery) application 1.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-5114

Disclosure Date: July 29, 2014 (last updated October 05, 2023)
WeBid 1.1.1 allows remote attackers to conduct an LDAP injection attack via the (1) js or (2) cat parameter.
0
Attacker Value
Unknown

CVE-2014-5101

Disclosure Date: July 25, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) TPL_name, (2) TPL_nick, (3) TPL_email, (4) TPL_year, (5) TPL_address, (6) TPL_city, (7) TPL_prov, (8) TPL_zip, (9) TPL_phone, (10) TPL_pp_email, (11) TPL_authnet_id, (12) TPL_authnet_pass, (13) TPL_worldpay_id, (14) TPL_toocheckout_id, or (15) TPL_moneybookers_email in a first action to register.php or the (16) username parameter in a login action to user_login.php.
0
Attacker Value
Unknown

CVE-2013-6774

Disclosure Date: March 31, 2014 (last updated October 05, 2023)
Untrusted search path vulnerability in the ChainsDD Superuser package 3.1.3 for Android 4.2.x and earlier, CyanogenMod/ClockWorkMod/Koush Superuser package 1.0.2.1 for Android 4.2.x and earlier, and Chainfire SuperSU package before 1.69 for Android 4.2.x and earlier allows attackers to load an arbitrary .jar file and gain privileges via a crafted BOOTCLASSPATH environment variable for a /system/xbin/su process. NOTE: another researcher was unable to reproduce this with ChainsDD Superuser.
0
Attacker Value
Unknown

CVE-2013-7139

Disclosure Date: January 09, 2014 (last updated October 05, 2023)
SQL injection vulnerability in download.php in Horizon Quick Content Management System (QCMS) 4.0 and earlier allows remote to execute arbitrary SQL commands via the category parameter.
0
Attacker Value
Unknown

CVE-2011-5021

Disclosure Date: December 29, 2011 (last updated October 04, 2023)
PHPIDS before 0.7 does not properly implement Regular Expression Denial of Service (ReDoS) filters, which allows remote attackers to bypass rulesets and add PHP sequences to a file via unspecified vectors.
0
Attacker Value
Unknown

CVE-2010-4873

Disclosure Date: October 07, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in confirm.php in WeBid 0.8.5 P1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
0