Show filters
107 Total Results
Displaying 81-90 of 107
Sort by:
Attacker Value
Unknown

CVE-2020-22224

Disclosure Date: November 05, 2021 (last updated February 23, 2025)
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the pjActionPreview function.
Attacker Value
Unknown

CVE-2020-22226

Disclosure Date: November 05, 2021 (last updated February 23, 2025)
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionSetAmount function.
Attacker Value
Unknown

CVE-2020-22225

Disclosure Date: November 05, 2021 (last updated February 23, 2025)
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoadForm function.
Attacker Value
Unknown

CVE-2020-22222

Disclosure Date: November 05, 2021 (last updated February 23, 2025)
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the pjActionLoadCss function.
Attacker Value
Unknown

CVE-2017-18225

Disclosure Date: March 12, 2018 (last updated November 26, 2024)
The Gentoo net-im/jabberd2 package through 2.6.1 installs jabberd, jabberd2-c2s, jabberd2-router, jabberd2-s2s, and jabberd2-sm in /usr/bin owned by the jabber account, which might allow local users to gain privileges by leveraging access to this account and then waiting for root to execute one of these programs.
0
Attacker Value
Unknown

CVE-2017-18226

Disclosure Date: March 12, 2018 (last updated November 26, 2024)
The Gentoo net-im/jabberd2 package through 2.6.1 sets the ownership of /var/run/jabber to the jabber account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script executes a "kill -TERM `cat /var/run/jabber/filename.pid`" command.
0
Attacker Value
Unknown

CVE-2017-15384

Disclosure Date: October 16, 2017 (last updated November 26, 2024)
rate-me.php in Rate Me 1.0 has XSS via the id field in a rate action.
0
Attacker Value
Unknown

CVE-2017-10807

Disclosure Date: July 04, 2017 (last updated November 26, 2024)
JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled.
0
Attacker Value
Unknown

CVE-2015-2058

Disclosure Date: August 12, 2015 (last updated October 05, 2023)
c2s/c2s.c in Jabber Open Source Server 2.3.2 and earlier truncates data without ensuring it remains valid UTF-8, which allows remote authenticated users to read system memory or possibly have other unspecified impact via a crafted JID.
0
Attacker Value
Unknown

CVE-2014-10001

Disclosure Date: January 13, 2015 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Appointment Scheduler 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks via the i18n[1][name] parameter in a pjActionCreate action to the pjAdminServices controller or (2) add an administrator via a pjActionCreate action to the pjAdminUsers controller.
0