Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2020-7990
Disclosure Date: January 26, 2020 (last updated February 21, 2025)
Adive Framework 2.0.8 has admin/user/add userName XSS.
0
Attacker Value
Unknown
CVE-2020-7991
Disclosure Date: January 26, 2020 (last updated February 21, 2025)
Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.
0
Attacker Value
Unknown
CVE-2020-7989
Disclosure Date: January 26, 2020 (last updated February 21, 2025)
Adive Framework 2.0.8 has admin/user/add userUsername XSS.
0
Attacker Value
Unknown
CVE-2018-6010
Disclosure Date: January 22, 2018 (last updated November 26, 2024)
In Yii Framework 2.x before 2.0.14, remote attackers could obtain potentially sensitive information from exception messages, or exploit reflected XSS on the error handler page in non-debug mode. Related to base/ErrorHandler.php, log/Dispatcher.php, and views/errorHandler/exception.php.
0
Attacker Value
Unknown
CVE-2018-6009
Disclosure Date: January 22, 2018 (last updated November 26, 2024)
In Yii Framework 2.x before 2.0.14, the switchIdentity function in web/User.php did not regenerate the CSRF token upon a change of identity.
0
Attacker Value
Unknown
CVE-2015-2156
Disclosure Date: October 18, 2017 (last updated November 08, 2023)
Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.
0