Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2023-27088

Disclosure Date: March 08, 2023 (last updated October 08, 2023)
feiqu-opensource Background Vertical authorization vulnerability exists in IndexController.java. demo users with low permission can perform operations within the permission of the admin super administrator and can use this vulnerability to change the blacklist IP address in the system at will.
Attacker Value
Unknown

CVE-2019-7436

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has directory traversal via a direct request for a listing of an uploads directory.
0
Attacker Value
Unknown

CVE-2019-7435

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has reflected HTML injection via the Search Form.
0
Attacker Value
Unknown

CVE-2019-7437

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has reflected Cross-Site Scripting (XSS) via the Search field.
0
Attacker Value
Unknown

CVE-2018-16278

Disclosure Date: August 31, 2018 (last updated November 27, 2024)
phpkaiyuancms PhpOpenSourceCMS (POSCMS) V3.2.0 allows an unauthenticated user to execute arbitrary SQL commands via the diy/module/member/controllers/Api.php ajax_save_draft function with the dir parameter.
0
Attacker Value
Unknown

CVE-2017-17623

Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
0
Attacker Value
Unknown

CVE-2012-5823

Disclosure Date: November 04, 2012 (last updated October 05, 2023)
Open Source Classifieds does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP fsockopen function.
0
Attacker Value
Unknown

CVE-2009-2346

Disclosure Date: September 08, 2009 (last updated August 16, 2024)
The IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2, 1.6.0.x before 1.6.0.15, and 1.6.1.x before 1.6.1.6; Business Edition B.x.x before B.2.5.10, C.2.x before C.2.4.3, and C.3.x before C.3.1.1; and s800i 1.3.x before 1.3.0.3 allows remote attackers to cause a denial of service (call-number exhaustion) by initiating many IAX2 message exchanges, a related issue to CVE-2008-3263.
0
Attacker Value
Unknown

CVE-2007-0354

Disclosure Date: January 19, 2007 (last updated October 04, 2023)
SQL injection vulnerability in email.php in MGB OpenSource Guestbook 0.5.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2006-5513

Disclosure Date: October 26, 2006 (last updated October 04, 2023)
SQL injection vulnerability in GeoNetwork opensource before 2.0.3 allows remote attackers to execute arbitrary SQL commands, and complete a login, via unspecified vectors.
0