Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2022-4974
Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
0
Attacker Value
Unknown
CVE-2024-5045
Disclosure Date: May 17, 2024 (last updated February 11, 2025)
A vulnerability was found in SourceCodester Online Birth Certificate Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin. The manipulation leads to files or directories accessible. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-264742 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2022-42067
Disclosure Date: October 14, 2022 (last updated October 08, 2023)
Online Birth Certificate Management System version 1.0 suffers from an Insecure Direct Object Reference (IDOR) vulnerability
0
Attacker Value
Unknown
CVE-2022-42071
Disclosure Date: October 14, 2022 (last updated October 08, 2023)
Online Birth Certificate Management System version 1.0 suffers from a Cross Site Scripting (XSS) Vulnerability.
0
Attacker Value
Unknown
CVE-2022-42070
Disclosure Date: October 14, 2022 (last updated October 08, 2023)
Online Birth Certificate Management System version 1.0 is vulnerable to Cross Site Request Forgery (CSRF).
0
Attacker Value
Unknown
CVE-2022-42069
Disclosure Date: October 14, 2022 (last updated October 08, 2023)
Online Birth Certificate Management System version 1.0 suffers from a persistent Cross Site Scripting (XSS) vulnerability.
0
Attacker Value
Unknown
CVE-2008-1676
Disclosure Date: July 07, 2008 (last updated October 04, 2023)
Red Hat PKI Common Framework (rhpki-common) in Red Hat Certificate System (aka Certificate Server or RHCS) 7.1 through 7.3, and Netscape Certificate Management System 6.x, does not recognize Certificate Authority profile constraints on Extensions, which might allow remote attackers to bypass intended restrictions and conduct man-in-the-middle attacks by submitting a certificate signing request (CSR) and using the resulting certificate.
0
Attacker Value
Unknown
CVE-2000-1076
Disclosure Date: December 11, 2000 (last updated February 22, 2025)
Netscape (iPlanet) Certificate Management System 4.2 and Directory Server 4.12 stores the administrative password in plaintext, which could allow local and possibly remote attackers to gain administrative privileges on the server.
0
Attacker Value
Unknown
CVE-2000-1075
Disclosure Date: December 11, 2000 (last updated February 22, 2025)
Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the Agent, End Entity, or Administrator services.
0