Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2022-4974
Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
0
Attacker Value
Unknown
CVE-2017-17896
Disclosure Date: December 27, 2017 (last updated November 26, 2024)
Readymade Job Site Script has XSS via the keyword parameter to the /job URI.
0
Attacker Value
Unknown
CVE-2017-17894
Disclosure Date: December 27, 2017 (last updated November 26, 2024)
Readymade Job Site Script has CSRF via the /job URI.
0
Attacker Value
Unknown
CVE-2017-17895
Disclosure Date: December 27, 2017 (last updated November 26, 2024)
Readymade Job Site Script has SQL Injection via the location_name array parameter to the /job URI.
0
Attacker Value
Unknown
CVE-2017-17642
Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.
0
Attacker Value
Unknown
CVE-2010-2610
Disclosure Date: July 02, 2010 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in 2daybiz Job Site Script allow remote attackers to execute arbitrary SQL commands via the (1) jid parameter to view_current_job.php, (2) job_iid parameter to show_search_more.php, and (3) left_cat parameter to show_search_result.php.
0