Show filters
150 Total Results
Displaying 81-90 of 150
Sort by:
Attacker Value
Unknown
CVE-2011-2933
Disclosure Date: January 14, 2020 (last updated February 21, 2025)
An Arbitrary File Upload vulnerability exists in admin/media/upload.php in WebsiteBaker 2.8.1 and earlier due to a failure to restrict uploaded files with .htaccess, .php4, .php5, and .phtl extensions.
0
Attacker Value
Unknown
CVE-2011-2934
Disclosure Date: January 14, 2020 (last updated February 21, 2025)
A Cross Site Request Forgery (CSRF) vulnerability exists in the administrator functions in WebsiteBaker 2.8.1 and earlier due to inadequate confirmation for sensitive transactions.
0
Attacker Value
Unknown
CVE-2019-15771
Disclosure Date: August 29, 2019 (last updated November 27, 2024)
The nd-shortcodes plugin before 6.0 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
0
Attacker Value
Unknown
CVE-2014-9699
Disclosure Date: June 24, 2019 (last updated November 27, 2024)
The MakerBot Replicator 5G printer runs an Apache HTTP Server with directory indexing enabled. Apache logs, system logs, design files (i.e., a history of print files), and more are exposed to unauthenticated attackers through this HTTP server.
0
Attacker Value
Unknown
CVE-2019-8982
Disclosure Date: February 21, 2019 (last updated November 27, 2024)
com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF.
0
Attacker Value
Unknown
CVE-2016-9045
Disclosure Date: September 17, 2018 (last updated November 27, 2024)
A code execution vulnerability exists in ProcessMaker Enterprise Core 3.0.1.7-community. A specially crafted web request can cause unsafe deserialization potentially resulting in PHP code being executed. An attacker can send a crafted web parameter to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2016-9048
Disclosure Date: September 10, 2018 (last updated November 27, 2024)
Multiple exploitable SQL Injection vulnerabilities exists in ProcessMaker Enterprise Core 3.0.1.7-community. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and in certain setups access the underlying operating system.
0
Attacker Value
Unknown
CVE-2017-16514
Disclosure Date: January 10, 2018 (last updated November 26, 2024)
Multiple persistent stored Cross-Site-Scripting (XSS) vulnerabilities in the files /wb/admin/admintools/tool.php (Droplet Description) and /install/index.php (Site Title) in WebsiteBaker 2.10.0 allow attackers to insert persistent JavaScript code that gets reflected back to users in multiple areas in the application.
0
Attacker Value
Unknown
CVE-2015-3160
Disclosure Date: September 06, 2017 (last updated November 26, 2024)
XML external entity (XXE) vulnerability in bkr/server/jobs.py in Beaker before 20.1 allows remote authenticated users to obtain sensitive information via submitting job XML to the server containing entity references which reference files from the Beaker server's file system.
0
Attacker Value
Unknown
CVE-2015-3161
Disclosure Date: September 06, 2017 (last updated November 26, 2024)
The search bar code in bkr/server/widgets.py in Beaker before 20.1 does not escape </script> tags in string literals when producing JSON.
0