Show filters
82 Total Results
Displaying 61-70 of 82
Sort by:
Attacker Value
Unknown

CVE-2020-7697

Disclosure Date: July 29, 2020 (last updated February 21, 2025)
This affects all versions of package mock2easy. a malicious user could inject commands through the _data variable: Affected Area require('../server/getJsonByCurl')(mock2easy, function (error, stdout) { if (error) { return res.json(500, error); } res.json(JSON.parse(stdout)); }, '', _data.interfaceUrl, query, _data.cookie,_data.interfaceType);
Attacker Value
Unknown

CVE-2020-7616

Disclosure Date: April 07, 2020 (last updated February 21, 2025)
express-mock-middleware through 0.0.6 is vulnerable to Prototype Pollution. Exported functions by the package can be tricked into adding or modifying properties of the `Object.prototype`. Exploitation of this vulnerability requires creation of a new directory where an attack code can be placed which will then be exported by `express-mock-middleware`. As such, this is considered to be a low risk.
Attacker Value
Unknown

python-dbusmock arbitrary code execution or file overwrite when templates are l…

Disclosure Date: April 22, 2019 (last updated November 27, 2024)
python-dbusmock before version 0.15.1 AddTemplate() D-Bus method call or DBusTestCase.spawn_server_template() method could be tricked into executing malicious code if an attacker supplies a .pyc file.
0
Attacker Value
Unknown

CVE-2018-13091

Disclosure Date: July 03, 2018 (last updated November 26, 2024)
The mintToken function of a smart contract implementation for sumocoin (SUMO), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
0
Attacker Value
Unknown

CVE-2017-16106

Disclosure Date: June 07, 2018 (last updated November 26, 2024)
tmock is a static file server. tmock is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
0
Attacker Value
Unknown

CVE-2017-16146

Disclosure Date: June 07, 2018 (last updated November 26, 2024)
mockserve is a file server. mockserve is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
0
Attacker Value
Unknown

CVE-2018-10429

Disclosure Date: April 26, 2018 (last updated November 26, 2024)
Cosmo 1.0.0Beta6 allows attackers to execute arbitrary PHP code via the Database Prefix field on the Database Info screen of install.php.
0
Attacker Value
Unknown

CVE-2018-9116

Disclosure Date: March 29, 2018 (last updated November 08, 2023)
An XXE vulnerability within WireMock before 2.16.0 allows a remote unauthenticated attacker to access local files and internal resources and potentially cause a Denial of Service.
0
Attacker Value
Unknown

CVE-2018-9117

Disclosure Date: March 29, 2018 (last updated November 08, 2023)
WireMock before 2.16.0 contains a vulnerability that allows a remote unauthenticated attacker to access local files beyond the application directory via a specially crafted XML request, aka Directory Traversal.
0
Attacker Value
Unknown

CVE-2017-2240

Disclosure Date: July 17, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in AssetView for MacOS Ver.9.2.0 and earlier versions allows remote attackers to read arbitrary files via "File Transfer Web Service".
0