Show filters
88 Total Results
Displaying 81-88 of 88
Sort by:
Attacker Value
Unknown
CVE-2012-5856
Disclosure Date: November 17, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Uk Cookie (aka uk-cookie) plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-6599
Disclosure Date: April 03, 2009 (last updated October 04, 2023)
cookiecheck.php in CookieCheck 1.0 stores tmp/cc_sessions under the web root with insufficient access control, which allows remote attackers to obtain session data via a direct request related to the "default session save path."
0
Attacker Value
Unknown
CVE-2006-4717
Disclosure Date: September 12, 2006 (last updated October 04, 2023)
The login redirection mechanism in the Drupal 4.7 Pubcookie module before 1.2.2.4 2006/09/06 and the Drupal 4.6 Pubcookie module before 1.6.2.1 2006/09/07 allows remote attackers to bypass authentication requirements and spoof identities of arbitrary users via unspecified vectors.
0
Attacker Value
Unknown
CVE-2006-1394
Disclosure Date: March 26, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in the Microsoft IIS ISAPI filter (aka application server module) in University of Washington Pubcookie 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified attack vectors.
0
Attacker Value
Unknown
CVE-2006-1393
Disclosure Date: March 26, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in the mod_pubcookie Apache application server module in University of Washington Pubcookie 1.x, 3.0.0, 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified attack vectors.
0
Attacker Value
Unknown
CVE-2006-1392
Disclosure Date: March 26, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in the login server in University of Washington Pubcookie 3.0.0, 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified inputs.
0
Attacker Value
Unknown
CVE-2005-1733
Disclosure Date: May 24, 2005 (last updated February 22, 2025)
Cookie Cart stores the password file under the web document root with insufficient access control, which allows remote attackers to obtain usernames and encrypted passwords via a direct request to passwd.txt.
0
Attacker Value
Unknown
CVE-2005-1732
Disclosure Date: May 24, 2005 (last updated February 22, 2025)
Cookie Cart allows remote attackers to read the Order Notification list via the testmycgi and path parameters to testmy.cgi.
0