Show filters
710 Total Results
Displaying 71-80 of 710
Sort by:
Attacker Value
Unknown
CVE-2023-20114
Disclosure Date: November 01, 2023 (last updated December 22, 2024)
A vulnerability in the file download feature of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to download arbitrary files from an affected system. This vulnerability is due to a lack of input sanitation. An attacker could exploit this vulnerability by sending a crafted HTTPS request. A successful exploit could allow the attacker to download arbitrary files from the affected system.
0
Attacker Value
Unknown
CVE-2023-20074
Disclosure Date: November 01, 2023 (last updated December 22, 2024)
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information. In some cases, it is also possible to cause a temporary availability impact to portions of the FMC Dashboard.
0
Attacker Value
Unknown
CVE-2023-20041
Disclosure Date: November 01, 2023 (last updated December 22, 2024)
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information. In some cases, it is also possible to cause a temporary availability impact to portions of the FMC Dashboard.
0
Attacker Value
Unknown
CVE-2023-20005
Disclosure Date: November 01, 2023 (last updated December 22, 2024)
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information. In some cases, it is also possible to cause a temporary availability impact to portions of the FMC Dashboard.
0
Attacker Value
Unknown
CVE-2023-36317
Disclosure Date: August 23, 2023 (last updated September 08, 2024)
Cross Site Scripting (XSS) vulnerability in sourcecodester Student Study Center Desk Management System 1.0 allows attackers to run arbitrary code via crafted GET request to web application URL.
0
Attacker Value
Unknown
CVE-2023-32267
Disclosure Date: August 11, 2023 (last updated October 08, 2023)
A potential vulnerability has been identified in OpenText / Micro Focus ArcSight Management Center. The vulnerability could be remotely exploited.
0
Attacker Value
Unknown
CVE-2023-37570
Disclosure Date: August 08, 2023 (last updated October 08, 2023)
This vulnerability exists in ESDS Emagic Data Center Management Suit due to non-expiry of session cookie.
By reusing the stolen cookie, a remote attacker could gain unauthorized access to the targeted system.
0
Attacker Value
Unknown
CVE-2023-37569
Disclosure Date: August 08, 2023 (last updated February 14, 2025)
This vulnerability exists in ESDS Emagic Data Center Management Suit due to lack of input sanitization in its Ping component. A remote authenticated attacker could exploit this by injecting OS commands on the targeted system.
Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code on targeted system.
0
Attacker Value
Unknown
CVE-2023-34735
Disclosure Date: June 29, 2023 (last updated October 08, 2023)
Property Cloud Platform Management Center 1.0 is vulnerable to error-based SQL injection.
0
Attacker Value
Unknown
CVE-2023-33580
Disclosure Date: June 26, 2023 (last updated November 15, 2023)
Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" field on Admin Profile page.
0