Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2021-24867

Disclosure Date: February 21, 2022 (last updated October 07, 2023)
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
Attacker Value
Unknown

CVE-2017-17614

Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Food Order Script 1.0 has SQL Injection via the /list city parameter.
0
Attacker Value
Unknown

CVE-2014-7683

Disclosure Date: October 21, 2014 (last updated October 05, 2023)
The Free Canadian Author Previews (aka com.booksellerscanada.authorpreview) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2008-1783

Disclosure Date: April 15, 2008 (last updated October 04, 2023)
Prozilla Reviews 1.0 allows remote attackers to delete arbitrary users via a modified UserID parameter in a direct request to siteadmin/DeleteUser.php.
0
Attacker Value
Unknown

CVE-2007-1817

Disclosure Date: April 02, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the Lykos Reviews (lykos_reviews) 1.00 module for Xoops allows remote attackers to execute arbitrary SQL commands via the uid parameter in a u action.
0