Show filters
104 Total Results
Displaying 91-100 of 104
Sort by:
Attacker Value
Unknown
CVE-2019-14807
Disclosure Date: August 09, 2019 (last updated November 27, 2024)
In the MobileFrontend extension 1.31 through 1.33 for MediaWiki, XSS exists within the edit summary field in includes/specials/MobileSpecialPageFeed.php.
0
Attacker Value
Unknown
CVE-2016-6846
Disclosure Date: March 29, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite backend before 7.6.2-rev59, 7.8.0 before 7.8.0-rev38, 7.8.2 before 7.8.2-rev8; AppSuite frontend before 7.6.2-rev47, 7.8.0 before 7.8.0-rev30, and 7.8.2 before 7.8.2-rev8; Office Web before 7.6.2-rev16, 7.8.0 before 7.8.0-rev10, and 7.8.2 before 7.8.2-rev5; and Documentconverter-API before 7.8.2-rev5 allows remote attackers to inject arbitrary web script or HTML.
0
Attacker Value
Unknown
CVE-2015-4607
Disclosure Date: June 16, 2015 (last updated October 05, 2023)
Unrestricted file upload vulnerability in the Frontend User Upload (feupload) extension 0.5.0 and earlier for TYPO3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension using a frontend form, then accessing it via a direct request to the file in the fileadmin folder.
0
Attacker Value
Unknown
CVE-2014-9444
Disclosure Date: January 02, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Frontend Uploader plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the errors[fu-disallowed-mime-type][0][name] parameter to the default URI.
0
Attacker Value
Unknown
CVE-2014-6231
Disclosure Date: September 11, 2014 (last updated October 05, 2023)
Unspecified vulnerability in the CWT Frontend Edit (cwt_feedit) extension before 1.2.5 for TYPO3 allows remote authenticated users to execute arbitrary code via unknown vectors.
0
Attacker Value
Unknown
CVE-2009-2103
Disclosure Date: June 17, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the Frontend MP3 Player (fe_mp3player) 0.2.3 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-4656
Disclosure Date: October 22, 2008 (last updated October 04, 2023)
SQL injection vulnerability in the Frontend Users View (feusersview) 0.1.6 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-3053
Disclosure Date: July 07, 2008 (last updated October 04, 2023)
SQL injection vulnerability in the SQL Frontend (mh_omsqlio) extension 1.0.11 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-3040
Disclosure Date: July 07, 2008 (last updated October 04, 2023)
Unspecified vulnerability in the DAM Frontend (dam_frontend) extension 0.1.0 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown vectors.
0
Attacker Value
Unknown
CVE-2008-3052
Disclosure Date: July 07, 2008 (last updated October 04, 2023)
Unspecified vulnerability in the SQL Frontend (mh_omsqlio) extension 1.0.11 and earlier for TYPO3 allows remote attackers to cause a denial of service via unknown vectors.
0