Show filters
250 Total Results
Displaying 91-100 of 250
Sort by:
Attacker Value
Unknown

CVE-2020-6932

Disclosure Date: August 12, 2020 (last updated November 28, 2024)
An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platform versions 6.4.0 to 6.6.0 could allow an attacker to potentially read arbitrary files and run arbitrary executables in the context of the web server.
Attacker Value
Unknown

CVE-2020-13695

Disclosure Date: June 01, 2020 (last updated February 21, 2025)
In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges to execute grep as root without a password, which allows an attacker to obtain sensitive information via a grep of a /root/*.db or /etc/shadow file.
Attacker Value
Unknown

CVE-2020-13694

Disclosure Date: June 01, 2020 (last updated February 21, 2025)
In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user can execute sudo mysql without a password, which means that the www-data user can execute arbitrary OS commands via the mysql -e option.
Attacker Value
Unknown

CVE-2020-13448

Disclosure Date: June 01, 2020 (last updated February 21, 2025)
QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via command injection in the servicestart parameter.
Attacker Value
Unknown

CVE-2020-11652

Disclosure Date: April 30, 2020 (last updated February 21, 2025)
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.
Attacker Value
Unknown

CVE-2020-9008

Disclosure Date: February 25, 2020 (last updated February 21, 2025)
Stored Cross-site scripting (XSS) vulnerability in Blackboard Learn/PeopleTool v9.1 allows users to inject arbitrary web script via the Tile widget in the People Tool profile editor.
Attacker Value
Unknown

CVE-2012-5828

Disclosure Date: February 10, 2020 (last updated February 21, 2025)
BlackBerry PlayBook before 2.1 has an Information Disclosure Vulnerability via a Web browser component error
Attacker Value
Unknown

CVE-2019-15497

Disclosure Date: August 26, 2019 (last updated November 27, 2024)
Black Box iCOMPEL 9.2.3 through 11.1.4, as used in ONELAN Net-Top-Box 9.2.3 through 11.1.4 and other products, has default credentials that allow remote attackers to access devices remotely via SSH, HTTP, HTTPS, and FTP.
0
Attacker Value
Unknown

CVE-2019-10687

Disclosure Date: August 21, 2019 (last updated November 27, 2024)
KBPublisher 6.0.2.1 has SQL Injection via the admin/index.php?module=report entry_id[0] parameter, the admin/index.php?module=log id parameter, or an index.php?View=print&id[]= request.
0
Attacker Value
Unknown

CVE-2019-15160

Disclosure Date: August 19, 2019 (last updated November 27, 2024)
The SweetXml (aka sweet_xml) package through 0.6.6 for Erlang and Elixir allows attackers to cause a denial of service (resource consumption) via an XML entity expansion attack with an inline DTD.
0