Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2024-13541

Disclosure Date: February 12, 2025 (last updated February 12, 2025)
The aDirectory – WordPress Directory Listing Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the adqs_delete_listing() function in all versions up to, and including, 2.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary posts.
Attacker Value
Unknown

CVE-2024-50420

Disclosure Date: October 29, 2024 (last updated October 29, 2024)
Unrestricted Upload of File with Dangerous Type vulnerability in adirectory aDirectory allows Upload a Web Shell to a Web Server.This issue affects aDirectory: from n/a through 1.3.
0
Attacker Value
Unknown

CVE-2007-2342

Disclosure Date: April 27, 2007 (last updated October 04, 2023)
SQL injection vulnerability in error.asp in CreaScripts CreaDirectory 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2006-6083.
0
Attacker Value
Unknown

CVE-2006-6083

Disclosure Date: November 24, 2006 (last updated October 04, 2023)
SQL injection vulnerability in search.asp in CreaScripts Creadirectory allows remote attackers to execute arbitrary SQL commands via the category parameter.
0
Attacker Value
Unknown

CVE-2006-6082

Disclosure Date: November 24, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in CreaScripts Creadirectory allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to addlisting.asp or the (2) search parameter to search.asp.
0
Attacker Value
Unknown

CVE-2002-0697

Disclosure Date: August 12, 2002 (last updated February 22, 2025)
Microsoft Metadirectory Services (MMS) 2.2 allows remote attackers to bypass authentication and modify sensitive data by using an LDAP client to directly connect to MMS and bypass the checks for MMS credentials.
0