Show filters
104 Total Results
Displaying 61-70 of 104
Sort by:
Attacker Value
Unknown
CVE-2020-12772
Disclosure Date: May 12, 2020 (last updated February 21, 2025)
An issue was discovered in Ignite Realtime Spark 2.8.3 (and the ROAR plugin for it) on Windows. A chat message can include an IMG element with a SRC attribute referencing an external host's IP address. Upon access to this external host, the (NT)LM hashes of the user are sent with the HTTP request. This allows an attacker to collect these hashes, crack them, and potentially compromise the computer. (ROAR can be configured for automatic access. Also, access can occur if the user clicks.)
0
Attacker Value
Unknown
CVE-2020-10793
Disclosure Date: March 23, 2020 (last updated February 21, 2025)
CodeIgniter through 4.0.0 allows remote attackers to gain privileges via a modified Email ID to the "Select Role of the User" page. NOTE: A contributor to the CodeIgniter framework argues that the issue should not be attributed to CodeIgniter. Furthermore, the blog post reference shows an unknown website built with the CodeIgniter framework but that CodeIgniter is not responsible for introducing this issue because the framework has never provided a login screen, nor any kind of login or user management facilities beyond a Session library. Also, another reporter indicates the issue is with a custom module/plugin to CodeIgniter, not CodeIgniter itself.
0
Attacker Value
Unknown
CVE-2019-20525
Disclosure Date: March 19, 2020 (last updated February 21, 2025)
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver parameter.
0
Attacker Value
Unknown
CVE-2019-20526
Disclosure Date: March 19, 2020 (last updated February 21, 2025)
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter.
0
Attacker Value
Unknown
CVE-2019-20527
Disclosure Date: March 19, 2020 (last updated February 21, 2025)
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter.
0
Attacker Value
Unknown
CVE-2019-20528
Disclosure Date: March 18, 2020 (last updated February 21, 2025)
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter.
0
Attacker Value
Unknown
CVE-2012-1915
Disclosure Date: January 09, 2020 (last updated February 21, 2025)
EllisLab CodeIgniter 2.1.2 allows remote attackers to bypass the xss_clean() Filter and perform XSS attacks.
0
Attacker Value
Unknown
CVE-2019-20365
Disclosure Date: January 08, 2020 (last updated February 21, 2025)
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via search to the Users/Group search page.
0
Attacker Value
Unknown
CVE-2019-20366
Disclosure Date: January 08, 2020 (last updated February 21, 2025)
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via isTrustStore to Manage Store Contents.
0
Attacker Value
Unknown
CVE-2019-20364
Disclosure Date: January 08, 2020 (last updated February 21, 2025)
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp.
0