Show filters
89 Total Results
Displaying 71-80 of 89
Sort by:
Attacker Value
Unknown
CVE-2019-10118
Disclosure Date: March 27, 2019 (last updated November 27, 2024)
Snipe-IT before 4.6.14 has XSS, as demonstrated by log_meta values and the user's last name in the API.
0
Attacker Value
Unknown
CVE-2014-9559
Disclosure Date: February 03, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in SnipSnap 0.5.2a, 1.0b1, and 1.0b2 allows remote attackers to inject arbitrary web script or HTML via the query parameter to /snipsnap-search.
0
Attacker Value
Unknown
CVE-2014-6737
Disclosure Date: September 27, 2014 (last updated October 05, 2023)
The Ultimate Target-Armored Sniper (aka air.wood.liame.ultimatetarget) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-5891
Disclosure Date: September 15, 2014 (last updated October 05, 2023)
The SnipSnap Coupon App (aka com.snipsnap.snipsnapapp) application 1.1.11 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-5624
Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The Sniper Shooter Free - Fun Game (aka com.fungamesforfree.snipershooter.free) application 2.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-2950
Disclosure Date: July 14, 2014 (last updated October 05, 2023)
Datum Systems SnIP on PSM-500 and PSM-4500 devices does not require authentication for FTP sessions, which allows remote attackers to obtain sensitive information via RETR commands.
0
Attacker Value
Unknown
CVE-2014-2951
Disclosure Date: July 14, 2014 (last updated October 05, 2023)
Datum Systems SnIP on PSM-500 and PSM-4500 devices has a hardcoded password of admin for the admin account, which makes it easier for remote attackers to obtain access via unspecified vectors.
0
Attacker Value
Unknown
CVE-2010-2126
Disclosure Date: June 01, 2010 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Snipe Gallery 3.1.5 allow remote attackers to execute arbitrary PHP code via a URL in the cfg_admin_path parameter to (1) index.php, (2) view.php, (3) image.php, (4) search.php, (5) admin/index.php, (6) admin/gallery/index.php, (7) admin/gallery/view.php, (8) admin/gallery/gallery.php, (9) admin/gallery/image.php, and (10) admin/gallery/crop.php.
0
Attacker Value
Unknown
CVE-2009-0529
Disclosure Date: February 11, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in SnippetMaster Webpage Editor 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the language parameter.
0
Attacker Value
Unknown
CVE-2009-0530
Disclosure Date: February 11, 2009 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in SnippetMaster 2.2.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) _SESSION[SCRIPT_PATH] parameter to includes/vars.inc.php and the (2) g_pcltar_lib_dir parameter to includes/tar_lib/pcltar.lib.php.
0