Show filters
150 Total Results
Displaying 81-90 of 150
Sort by:
Attacker Value
Unknown

CVE-2011-2933

Disclosure Date: January 14, 2020 (last updated February 21, 2025)
An Arbitrary File Upload vulnerability exists in admin/media/upload.php in WebsiteBaker 2.8.1 and earlier due to a failure to restrict uploaded files with .htaccess, .php4, .php5, and .phtl extensions.
Attacker Value
Unknown

CVE-2011-2934

Disclosure Date: January 14, 2020 (last updated February 21, 2025)
A Cross Site Request Forgery (CSRF) vulnerability exists in the administrator functions in WebsiteBaker 2.8.1 and earlier due to inadequate confirmation for sensitive transactions.
Attacker Value
Unknown

CVE-2019-15771

Disclosure Date: August 29, 2019 (last updated November 27, 2024)
The nd-shortcodes plugin before 6.0 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
0
Attacker Value
Unknown

CVE-2014-9699

Disclosure Date: June 24, 2019 (last updated November 27, 2024)
The MakerBot Replicator 5G printer runs an Apache HTTP Server with directory indexing enabled. Apache logs, system logs, design files (i.e., a history of print files), and more are exposed to unauthenticated attackers through this HTTP server.
0
Attacker Value
Unknown

CVE-2019-8982

Disclosure Date: February 21, 2019 (last updated November 27, 2024)
com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF.
0
Attacker Value
Unknown

CVE-2016-9045

Disclosure Date: September 17, 2018 (last updated November 27, 2024)
A code execution vulnerability exists in ProcessMaker Enterprise Core 3.0.1.7-community. A specially crafted web request can cause unsafe deserialization potentially resulting in PHP code being executed. An attacker can send a crafted web parameter to trigger this vulnerability.
Attacker Value
Unknown

CVE-2016-9048

Disclosure Date: September 10, 2018 (last updated November 27, 2024)
Multiple exploitable SQL Injection vulnerabilities exists in ProcessMaker Enterprise Core 3.0.1.7-community. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and in certain setups access the underlying operating system.
Attacker Value
Unknown

CVE-2017-16514

Disclosure Date: January 10, 2018 (last updated November 26, 2024)
Multiple persistent stored Cross-Site-Scripting (XSS) vulnerabilities in the files /wb/admin/admintools/tool.php (Droplet Description) and /install/index.php (Site Title) in WebsiteBaker 2.10.0 allow attackers to insert persistent JavaScript code that gets reflected back to users in multiple areas in the application.
0
Attacker Value
Unknown

CVE-2015-3160

Disclosure Date: September 06, 2017 (last updated November 26, 2024)
XML external entity (XXE) vulnerability in bkr/server/jobs.py in Beaker before 20.1 allows remote authenticated users to obtain sensitive information via submitting job XML to the server containing entity references which reference files from the Beaker server's file system.
0
Attacker Value
Unknown

CVE-2015-3161

Disclosure Date: September 06, 2017 (last updated November 26, 2024)
The search bar code in bkr/server/widgets.py in Beaker before 20.1 does not escape </script> tags in string literals when producing JSON.
0