Show filters
116 Total Results
Displaying 1-10 of 116
Sort by:
Attacker Value
Moderate

Heap overflow in glibc 2.2 name resolution (CVE-2015-0235)

Disclosure Date: January 28, 2015 (last updated October 05, 2023)
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."
1
Attacker Value
Unknown

CVE-2023-38876

Disclosure Date: September 20, 2023 (last updated October 08, 2023)
A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'selector' parameter in '/reset-password'.
Attacker Value
Unknown

CVE-2023-38875

Disclosure Date: September 20, 2023 (last updated October 08, 2023)
A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'validator' parameter in '/reset-password'.
Attacker Value
Unknown

CVE-2023-3538

Disclosure Date: July 07, 2023 (last updated October 08, 2023)
A vulnerability classified as problematic was found in SimplePHPscripts Photo Gallery PHP 2.0. This vulnerability affects unknown code of the file /preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. VDB-233290 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2020-28062

Disclosure Date: April 04, 2022 (last updated October 07, 2023)
An Access Control vulnerability exists in HisiPHP 2.0.11 via special packets that are constructed in $files = Dir::getList($decompath. '/ Upload/Plugins /, which could let a remote malicious user execute arbitrary code.
Attacker Value
Unknown

CVE-2020-21130

Disclosure Date: June 21, 2021 (last updated November 28, 2024)
Cross Site Scripting (XSS) vulnerability in HisiPHP 2.0.8 via the group name in addgroup.html.
Attacker Value
Unknown

CVE-2018-11209

Disclosure Date: May 16, 2018 (last updated November 08, 2023)
An issue was discovered in Z-BlogPHP 2.0.0. zb_system/cmd.php?act=verify relies on MD5 for the password parameter, which might make it easier for attackers to bypass intended access restrictions via a dictionary or rainbow-table attack. NOTE: the vendor declined to accept this as a valid issue
0
Attacker Value
Unknown

CVE-2018-11208

Disclosure Date: May 16, 2018 (last updated November 08, 2023)
An issue was discovered in Z-BlogPHP 2.0.0. There is a persistent XSS that allows remote attackers to inject arbitrary web script or HTML into background web site settings via the "copyright information office" field. NOTE: the vendor indicates that the product was not intended to block this type of XSS by a user with the admin privilege
0
Attacker Value
Unknown

CVE-2016-9814

Disclosure Date: February 17, 2017 (last updated November 26, 2024)
The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x before 1.10.3, and 2.x before 2.3.3 allows remote attackers to spoof SAML responses or possibly cause a denial of service (memory consumption) by leveraging improper conversion of return values to boolean.
0
Attacker Value
Unknown

CVE-2015-8379

Disclosure Date: January 26, 2016 (last updated November 25, 2024)
CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.
0