Show filters
252 Total Results
Displaying 71-80 of 252
Sort by:
Attacker Value
Unknown

CVE-2017-5971

Disclosure Date: January 08, 2018 (last updated November 26, 2024)
SQL injection vulnerability in NewsBee CMS allow remote attackers to execute arbitrary SQL commands.
0
Attacker Value
Unknown

CVE-2017-14500

Disclosure Date: September 17, 2017 (last updated November 26, 2024)
Improper Neutralization of Special Elements used in an OS Command in the podcast playback function of Podbeuter in Newsbeuter 0.3 through 2.9 allows remote attackers to perform user-assisted code execution by crafting an RSS item with a media enclosure (i.e., a podcast file) that includes shell metacharacters in its filename, related to pb_controller.cpp and queueloader.cpp, a different vulnerability than CVE-2017-12904.
0
Attacker Value
Unknown

CVE-2017-12904

Disclosure Date: August 23, 2017 (last updated November 08, 2023)
Improper Neutralization of Special Elements used in an OS Command in bookmarking function of Newsbeuter versions 0.7 through 2.9 allows remote attackers to perform user-assisted code execution by crafting an RSS item that includes shell code in its title and/or URL.
0
Attacker Value
Unknown

CVE-2017-7581

Disclosure Date: April 07, 2017 (last updated November 26, 2024)
SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand for order and OrderByAllowed.
0
Attacker Value
Unknown

CVE-2015-4063

Disclosure Date: May 27, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the where1 parameter in the nsp_search page to wp-admin/admin.php.
0
Attacker Value
Unknown

CVE-2015-4062

Disclosure Date: May 27, 2015 (last updated October 05, 2023)
SQL injection vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the where1 parameter in the nsp_search page to wp-admin/admin.php.
0
Attacker Value
Unknown

CVE-2015-3369

Disclosure Date: April 21, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Taxonews module before 6.x-1.2 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via a term name in a block.
0
Attacker Value
Unknown

CVE-2014-7632

Disclosure Date: October 21, 2014 (last updated October 05, 2023)
The news revolution - bahrain (aka com.news.revolution.BH) application 3.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-7698

Disclosure Date: October 21, 2014 (last updated October 05, 2023)
The Xinhua International (aka org.xinhua.xnews_international) application 5.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-7580

Disclosure Date: October 20, 2014 (last updated October 05, 2023)
The Thailand Investor News (aka nudecreative.thaistock.set) application 1.39s for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0