Show filters
88 Total Results
Displaying 71-80 of 88
Sort by:
Attacker Value
Unknown

CVE-2017-18589

Disclosure Date: August 26, 2019 (last updated November 27, 2024)
An issue was discovered in the cookie crate before 0.7.6 for Rust. Large integers in the Max-Age of a cookie cause a panic.
0
Attacker Value
Unknown

CVE-2016-1000232

Disclosure Date: September 05, 2018 (last updated November 27, 2024)
NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial of Service. This attack appear to be exploitable via Custom HTTP header passed by client. This vulnerability appears to have been fixed in 2.3.0.
0
Attacker Value
Unknown

CVE-2018-10371

Disclosure Date: May 01, 2018 (last updated November 26, 2024)
An issue was discovered in the wunderfarm WF Cookie Consent plugin 1.1.3 for WordPress. A persistent cross-site scripting vulnerability has been identified in the web interface of the plugin that allows the execution of arbitrary HTML/script code to be executed in a victim's web browser via a page title.
0
Attacker Value
Unknown

CVE-2018-10310

Disclosure Date: April 25, 2018 (last updated November 26, 2024)
A persistent cross-site scripting vulnerability has been identified in the web interface of the Catapult UK Cookie Consent plugin before 2.3.10 for WordPress that allows the execution of arbitrary HTML/script code in the context of a victim's browser.
0
Attacker Value
Unknown

CVE-2018-10309

Disclosure Date: April 24, 2018 (last updated November 26, 2024)
The Responsive Cookie Consent plugin before 1.8 for WordPress mishandles number fields, leading to XSS.
0
Attacker Value
Unknown

CVE-2017-15010

Disclosure Date: October 04, 2017 (last updated November 08, 2023)
A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module before 2.3.3 for Node.js. An attacker that is able to make an HTTP request using a specially crafted cookie may cause the application to consume an excessive amount of CPU.
0
Attacker Value
Unknown

CVE-2014-8352

Disclosure Date: November 06, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in json.php in French National Commission on Informatics and Liberty (aka CNIL) CookieViz allows remote we servers to inject arbitrary web script or HTML via the max_date parameter.
0
Attacker Value
Unknown

CVE-2014-8351

Disclosure Date: November 06, 2014 (last updated October 05, 2023)
SQL injection vulnerability in info.php in French National Commission on Informatics and Liberty (aka CNIL) CookieViz before 1.0.1 allows remote web servers to execute arbitrary SQL commands via the domain parameter.
0
Attacker Value
Unknown

CVE-2013-7064

Disclosure Date: April 29, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the EU Cookie Compliance module 7.x-1.x before 7.x-1.12 for Drupal allows remote authenticated administrators with the "Administer EU Cookie Compliance popup" permission to inject arbitrary web script or HTML via unspecified configuration values.
0
Attacker Value
Unknown

CVE-2012-6312

Disclosure Date: December 11, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Video Lead Form plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the errMsg parameter in a video-lead-form action to wp-admin/admin.php.
0