Show filters
96 Total Results
Displaying 81-90 of 96
Sort by:
Attacker Value
Unknown
CVE-2016-1000112
Disclosure Date: October 06, 2016 (last updated November 25, 2024)
Unauthenticated remote .jpg file upload in contus-video-comments v1.0 wordpress plugin
0
Attacker Value
Unknown
CVE-2014-4565
Disclosure Date: July 02, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in vcc.js.php in the Verification Code for Comments plugin 2.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) vp, (2) vs, (3) l, (4) vu, or (5) vm parameter.
0
Attacker Value
Unknown
CVE-2014-4163
Disclosure Date: June 16, 2014 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in the Featured Comments plugin 1.2.1 for WordPress allow remote attackers to hijack the authentication of administrators for requests that change the (1) buried or (2) featured status of a comment via a request to wp-admin/admin-ajax.php.
0
Attacker Value
Unknown
CVE-2012-1068
Disclosure Date: February 14, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the rc_ajax function in core.php in the WP-RecentComments plugin before 2.0.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter, related to AJAX paging.
0
Attacker Value
Unknown
CVE-2012-1067
Disclosure Date: February 14, 2012 (last updated October 04, 2023)
SQL injection vulnerability in the WP-RecentComments plugin 2.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter in an rc-content action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2010-5048
Disclosure Date: November 23, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in admin.jcomments.php in the JoomlaTune JComments (com_jcomments) component 2.1.0.0 for Joomla! allows remote authenticated users to inject arbitrary web script or HTML via the name parameter to index.php.
0
Attacker Value
Unknown
CVE-2010-4887
Disclosure Date: October 07, 2011 (last updated October 04, 2023)
SQL injection vulnerability in the Commenting system Backend Module (commentsbe) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2010-4516
Disclosure Date: December 09, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the JXtended Comments component before 1.3.1 for Joomla allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2010-2464
Disclosure Date: June 25, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the RSComments (com_rscomments) component 1.0.0 Rev 2 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) website and (2) name parameters to index.php.
0
Attacker Value
Unknown
CVE-2009-4505
Disclosure Date: March 26, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in OpenCMS OAMP Comments Module 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the name field in a comment, and other unspecified vectors.
0