Show filters
356 Total Results
Displaying 81-90 of 356
Sort by:
Attacker Value
Unknown
CVE-2023-0452
Disclosure Date: January 26, 2023 (last updated October 08, 2023)
Econolite EOS versions prior to 3.2.23 use a weak hash
algorithm for encrypting privileged user credentials. A configuration file that
is accessible without authentication uses MD5 hashes for encrypting
credentials, including those of administrators and technicians.
0
Attacker Value
Unknown
CVE-2023-0451
Disclosure Date: January 26, 2023 (last updated October 08, 2023)
Econolite EOS versions prior to 3.2.23 lack a password
requirement for gaining “READONLY” access to log files and certain database and
configuration files. One such file contains tables with MD5 hashes and
usernames for all defined users in the control software, including
administrators and technicians.
0
Attacker Value
Unknown
CVE-2022-25847
Disclosure Date: January 26, 2023 (last updated November 08, 2023)
All versions of the package serve-lite are vulnerable to Cross-site Scripting (XSS) because when it detects a request to a directory, it renders a file listing of all of its contents with links that include the actual file names without any sanitization or output encoding.
0
Attacker Value
Unknown
CVE-2022-21192
Disclosure Date: January 26, 2023 (last updated November 08, 2023)
All versions of the package serve-lite are vulnerable to Directory Traversal due to missing input sanitization or other checks and protections employed to the req.url passed as-is to path.join().
0
Attacker Value
Unknown
CVE-2022-4369
Disclosure Date: January 02, 2023 (last updated October 08, 2023)
The WP-Lister Lite for Amazon WordPress plugin before 2.4.4 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which can be used against high-privilege users such as admin.
0
Attacker Value
Unknown
CVE-2022-25895
Disclosure Date: December 21, 2022 (last updated October 08, 2023)
All versions of package lite-dev-server are vulnerable to Directory Traversal due to missing input sanitization and sandboxes being employed to the req.url user input that is passed to the server code.
0
Attacker Value
Unknown
CVE-2022-25940
Disclosure Date: December 20, 2022 (last updated October 08, 2023)
All versions of package lite-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control characters that the decodeURI() function is unable to parse.
0
Attacker Value
Unknown
CVE-2022-4410
Disclosure Date: December 14, 2022 (last updated October 08, 2023)
The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including 2.2.20.3 due to improper output escaping on post/page/media titles. This makes it possible for attackers to inject arbitrary web scripts on the permalink-manager page if another plugin or theme is installed on the site that allows lower privileged users with unfiltered_html the ability to modify post/page titles with malicious web scripts.
0
Attacker Value
Unknown
CVE-2022-46908
Disclosure Date: December 12, 2022 (last updated October 08, 2023)
SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions such as WRITEFILE.
0
Attacker Value
Unknown
CVE-2022-4021
Disclosure Date: November 16, 2022 (last updated November 08, 2023)
The Permalink Manager Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.20.1. This is due to missing or incorrect nonce validation on the extra_actions function. This makes it possible for unauthenticated attackers to change plugin settings including permalinks and site maps, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0