Show filters
88 Total Results
Displaying 81-88 of 88
Sort by:
Attacker Value
Unknown

CVE-2012-5856

Disclosure Date: November 17, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Uk Cookie (aka uk-cookie) plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-6599

Disclosure Date: April 03, 2009 (last updated October 04, 2023)
cookiecheck.php in CookieCheck 1.0 stores tmp/cc_sessions under the web root with insufficient access control, which allows remote attackers to obtain session data via a direct request related to the "default session save path."
0
Attacker Value
Unknown

CVE-2006-4717

Disclosure Date: September 12, 2006 (last updated October 04, 2023)
The login redirection mechanism in the Drupal 4.7 Pubcookie module before 1.2.2.4 2006/09/06 and the Drupal 4.6 Pubcookie module before 1.6.2.1 2006/09/07 allows remote attackers to bypass authentication requirements and spoof identities of arbitrary users via unspecified vectors.
0
Attacker Value
Unknown

CVE-2006-1394

Disclosure Date: March 26, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in the Microsoft IIS ISAPI filter (aka application server module) in University of Washington Pubcookie 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified attack vectors.
0
Attacker Value
Unknown

CVE-2006-1393

Disclosure Date: March 26, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in the mod_pubcookie Apache application server module in University of Washington Pubcookie 1.x, 3.0.0, 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified attack vectors.
0
Attacker Value
Unknown

CVE-2006-1392

Disclosure Date: March 26, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in the login server in University of Washington Pubcookie 3.0.0, 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified inputs.
0
Attacker Value
Unknown

CVE-2005-1733

Disclosure Date: May 24, 2005 (last updated February 22, 2025)
Cookie Cart stores the password file under the web document root with insufficient access control, which allows remote attackers to obtain usernames and encrypted passwords via a direct request to passwd.txt.
0
Attacker Value
Unknown

CVE-2005-1732

Disclosure Date: May 24, 2005 (last updated February 22, 2025)
Cookie Cart allows remote attackers to read the Order Notification list via the testmycgi and path parameters to testmy.cgi.
0