Show filters
406 Total Results
Displaying 81-90 of 406
Sort by:
Attacker Value
Unknown
CVE-2023-6271
Disclosure Date: January 01, 2024 (last updated January 09, 2024)
The Backup Migration WordPress plugin before 1.3.6 stores in-progress backups information in easy to find, publicly-accessible files, which may allow attackers monitoring those to leak sensitive information from the site's backups.
0
Attacker Value
Unknown
CVE-2023-4675
Disclosure Date: December 29, 2023 (last updated January 06, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GM Information Technologies MDO allows SQL Injection.This issue affects MDO: through 20231229.
NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2023-7002
Disclosure Date: December 23, 2023 (last updated December 29, 2023)
The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the 'url' parameter. This vulnerability allows authenticated attackers, with administrator-level permissions and above, to execute arbitrary commands on the host operating system.
0
Attacker Value
Unknown
CVE-2023-6972
Disclosure Date: December 23, 2023 (last updated December 29, 2023)
The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and 'content-name', 'content-manifest', or 'content-bmitmp' and 'content-identy' HTTP headers. This makes it possible for unauthenticated attackers to delete arbitrary files, including the wp-config.php file, which can make site takeover and remote code execution possible.
0
Attacker Value
Unknown
CVE-2023-6971
Disclosure Date: December 23, 2023 (last updated December 29, 2023)
The Backup Migration plugin for WordPress is vulnerable to Remote File Inclusion in versions 1.0.8 to 1.3.9 via the 'content-dir' HTTP header. This makes it possible for unauthenticated attackers to include remote files on the server, resulting in code execution. NOTE: Successful exploitation of this vulnerability requires that the target server's php.ini is configured with 'allow_url_include' set to 'on'. This feature is deprecated as of PHP 7.4 and is disabled by default, but can still be explicitly enabled in later versions of PHP.
0
Attacker Value
Unknown
CVE-2023-6341
Disclosure Date: November 30, 2023 (last updated December 09, 2023)
Catalis (previously Icon Software) CMS360 allows a remote, unauthenticated attacker to view sensitive court documents by modifying document and other identifiers in URLs. The impact varies based on the intention and configuration of a specific CMS360 installation.
0
Attacker Value
Unknown
CVE-2023-47649
Disclosure Date: November 18, 2023 (last updated November 25, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in PriceListo Best Restaurant Menu by PriceListo.This issue affects Best Restaurant Menu by PriceListo: from n/a through 1.3.1.
0
Attacker Value
Unknown
CVE-2023-47237
Disclosure Date: November 09, 2023 (last updated November 15, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Martin Gibson Auto Publish for Google My Business plugin <= 3.7 versions.
0
Attacker Value
Unknown
CVE-2023-25994
Disclosure Date: November 09, 2023 (last updated November 16, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Alex Benfica Publish to Schedule plugin <= 4.4.2 versions.
0
Attacker Value
Unknown
CVE-2023-39924
Disclosure Date: October 25, 2023 (last updated November 01, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mitchell Bennis Simple File List plugin <= 6.1.9 versions.
0