Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2014-9919
Disclosure Date: May 15, 2019 (last updated November 27, 2024)
An issue was discovered in Bilboplanet 2.0. Stored XSS exists in the fullname parameter to signup.php.
0
Attacker Value
Unknown
CVE-2014-9918
Disclosure Date: May 15, 2019 (last updated November 27, 2024)
An issue was discovered in Bilboplanet 2.0. Stored XSS exists in the user_id parameter to signup.php.
0
Attacker Value
Unknown
CVE-2014-9917
Disclosure Date: May 15, 2019 (last updated November 27, 2024)
An issue was discovered in Bilboplanet 2.0. There is a stored XSS vulnerability when adding a tag via the user/?page=tribes tags parameter.
0
Attacker Value
Unknown
CVE-2014-9916
Disclosure Date: February 24, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in Bilboplanet 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) tribe_name or (2) tags parameter in a tribes page request to user/ or the (3) user_id or (4) fullname parameter to signup.php.
0
Attacker Value
Unknown
CVE-2013-1620
Disclosure Date: February 08, 2013 (last updated October 05, 2023)
The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.
0
Attacker Value
Unknown
CVE-2009-2937
Disclosure Date: September 18, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Planet 2.0 and Planet Venus allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of an IMG element in a feed.
0
Attacker Value
Unknown
CVE-2002-1654
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
iPlanet Web Server Enterprise Edition and Netscape Enterprise Server 4.0 and 4.1 allows remote attackers to conduct HTTP Basic Authentication via the wp-force-auth Web Publisher command, which provides a distinct attack vector and may make it easier to conduct brute force password guessing without detection.
0