Show filters
107 Total Results
Displaying 81-90 of 107
Sort by:
Attacker Value
Unknown
CVE-2020-22224
Disclosure Date: November 05, 2021 (last updated February 23, 2025)
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the pjActionPreview function.
0
Attacker Value
Unknown
CVE-2020-22226
Disclosure Date: November 05, 2021 (last updated February 23, 2025)
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionSetAmount function.
0
Attacker Value
Unknown
CVE-2020-22225
Disclosure Date: November 05, 2021 (last updated February 23, 2025)
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoadForm function.
0
Attacker Value
Unknown
CVE-2020-22222
Disclosure Date: November 05, 2021 (last updated February 23, 2025)
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the pjActionLoadCss function.
0
Attacker Value
Unknown
CVE-2017-18225
Disclosure Date: March 12, 2018 (last updated November 26, 2024)
The Gentoo net-im/jabberd2 package through 2.6.1 installs jabberd, jabberd2-c2s, jabberd2-router, jabberd2-s2s, and jabberd2-sm in /usr/bin owned by the jabber account, which might allow local users to gain privileges by leveraging access to this account and then waiting for root to execute one of these programs.
0
Attacker Value
Unknown
CVE-2017-18226
Disclosure Date: March 12, 2018 (last updated November 26, 2024)
The Gentoo net-im/jabberd2 package through 2.6.1 sets the ownership of /var/run/jabber to the jabber account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script executes a "kill -TERM `cat /var/run/jabber/filename.pid`" command.
0
Attacker Value
Unknown
CVE-2017-15384
Disclosure Date: October 16, 2017 (last updated November 26, 2024)
rate-me.php in Rate Me 1.0 has XSS via the id field in a rate action.
0
Attacker Value
Unknown
CVE-2017-10807
Disclosure Date: July 04, 2017 (last updated November 26, 2024)
JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled.
0
Attacker Value
Unknown
CVE-2015-2058
Disclosure Date: August 12, 2015 (last updated October 05, 2023)
c2s/c2s.c in Jabber Open Source Server 2.3.2 and earlier truncates data without ensuring it remains valid UTF-8, which allows remote authenticated users to read system memory or possibly have other unspecified impact via a crafted JID.
0
Attacker Value
Unknown
CVE-2014-10001
Disclosure Date: January 13, 2015 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Appointment Scheduler 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks via the i18n[1][name] parameter in a pjActionCreate action to the pjAdminServices controller or (2) add an administrator via a pjActionCreate action to the pjAdminUsers controller.
0