Show filters
104 Total Results
Displaying 91-100 of 104
Sort by:
Attacker Value
Unknown

CVE-2019-14807

Disclosure Date: August 09, 2019 (last updated November 27, 2024)
In the MobileFrontend extension 1.31 through 1.33 for MediaWiki, XSS exists within the edit summary field in includes/specials/MobileSpecialPageFeed.php.
Attacker Value
Unknown

CVE-2016-6846

Disclosure Date: March 29, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite backend before 7.6.2-rev59, 7.8.0 before 7.8.0-rev38, 7.8.2 before 7.8.2-rev8; AppSuite frontend before 7.6.2-rev47, 7.8.0 before 7.8.0-rev30, and 7.8.2 before 7.8.2-rev8; Office Web before 7.6.2-rev16, 7.8.0 before 7.8.0-rev10, and 7.8.2 before 7.8.2-rev5; and Documentconverter-API before 7.8.2-rev5 allows remote attackers to inject arbitrary web script or HTML.
0
Attacker Value
Unknown

CVE-2015-4607

Disclosure Date: June 16, 2015 (last updated October 05, 2023)
Unrestricted file upload vulnerability in the Frontend User Upload (feupload) extension 0.5.0 and earlier for TYPO3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension using a frontend form, then accessing it via a direct request to the file in the fileadmin folder.
0
Attacker Value
Unknown

CVE-2014-9444

Disclosure Date: January 02, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Frontend Uploader plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the errors[fu-disallowed-mime-type][0][name] parameter to the default URI.
0
Attacker Value
Unknown

CVE-2014-6231

Disclosure Date: September 11, 2014 (last updated October 05, 2023)
Unspecified vulnerability in the CWT Frontend Edit (cwt_feedit) extension before 1.2.5 for TYPO3 allows remote authenticated users to execute arbitrary code via unknown vectors.
0
Attacker Value
Unknown

CVE-2009-2103

Disclosure Date: June 17, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the Frontend MP3 Player (fe_mp3player) 0.2.3 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-4656

Disclosure Date: October 22, 2008 (last updated October 04, 2023)
SQL injection vulnerability in the Frontend Users View (feusersview) 0.1.6 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-3053

Disclosure Date: July 07, 2008 (last updated October 04, 2023)
SQL injection vulnerability in the SQL Frontend (mh_omsqlio) extension 1.0.11 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-3040

Disclosure Date: July 07, 2008 (last updated October 04, 2023)
Unspecified vulnerability in the DAM Frontend (dam_frontend) extension 0.1.0 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown vectors.
0
Attacker Value
Unknown

CVE-2008-3052

Disclosure Date: July 07, 2008 (last updated October 04, 2023)
Unspecified vulnerability in the SQL Frontend (mh_omsqlio) extension 1.0.11 and earlier for TYPO3 allows remote attackers to cause a denial of service via unknown vectors.
0