Show filters
96 Total Results
Displaying 81-90 of 96
Sort by:
Attacker Value
Unknown

CVE-2016-1000112

Disclosure Date: October 06, 2016 (last updated November 25, 2024)
Unauthenticated remote .jpg file upload in contus-video-comments v1.0 wordpress plugin
Attacker Value
Unknown

CVE-2014-4565

Disclosure Date: July 02, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in vcc.js.php in the Verification Code for Comments plugin 2.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) vp, (2) vs, (3) l, (4) vu, or (5) vm parameter.
0
Attacker Value
Unknown

CVE-2014-4163

Disclosure Date: June 16, 2014 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in the Featured Comments plugin 1.2.1 for WordPress allow remote attackers to hijack the authentication of administrators for requests that change the (1) buried or (2) featured status of a comment via a request to wp-admin/admin-ajax.php.
0
Attacker Value
Unknown

CVE-2012-1068

Disclosure Date: February 14, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the rc_ajax function in core.php in the WP-RecentComments plugin before 2.0.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter, related to AJAX paging.
0
Attacker Value
Unknown

CVE-2012-1067

Disclosure Date: February 14, 2012 (last updated October 04, 2023)
SQL injection vulnerability in the WP-RecentComments plugin 2.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter in an rc-content action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2010-5048

Disclosure Date: November 23, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in admin.jcomments.php in the JoomlaTune JComments (com_jcomments) component 2.1.0.0 for Joomla! allows remote authenticated users to inject arbitrary web script or HTML via the name parameter to index.php.
0
Attacker Value
Unknown

CVE-2010-4887

Disclosure Date: October 07, 2011 (last updated October 04, 2023)
SQL injection vulnerability in the Commenting system Backend Module (commentsbe) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2010-4516

Disclosure Date: December 09, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the JXtended Comments component before 1.3.1 for Joomla allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2010-2464

Disclosure Date: June 25, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the RSComments (com_rscomments) component 1.0.0 Rev 2 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) website and (2) name parameters to index.php.
0
Attacker Value
Unknown

CVE-2009-4505

Disclosure Date: March 26, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in OpenCMS OAMP Comments Module 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the name field in a comment, and other unspecified vectors.
0