Show filters
24 Total Results
Displaying 1-10 of 24
Sort by:
Attacker Value
Unknown

CVE-2022-4974

Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Attacker Value
Unknown

CVE-2020-3940

Disclosure Date: January 17, 2020 (last updated February 21, 2025)
VMware Workspace ONE SDK and dependent mobile application updates address sensitive information disclosure vulnerability.
Attacker Value
Unknown

CVE-2018-19371

Disclosure Date: January 02, 2019 (last updated November 27, 2024)
The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive files from the system.
0
Attacker Value
Unknown

CVE-2016-8922

Disclosure Date: February 01, 2017 (last updated November 25, 2024)
Exphox WebRadar is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
0
Attacker Value
Unknown

CVE-2016-2901

Disclosure Date: June 26, 2016 (last updated November 25, 2024)
Cross-site request forgery (CSRF) vulnerability in the PA_Theme_Creator application in IBM WebSphere Portal 8.5 CF08 through CF10 and Web Content Manager allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
0
Attacker Value
Unknown

CVE-2013-6329

Disclosure Date: December 17, 2013 (last updated October 05, 2023)
IBM Global Security Kit (aka GSKit), as used in Content Manager OnDemand 8.5 and 9.0 and other products, allows remote attackers to cause a denial of service via a crafted handshake during resumption of an SSLv2 session.
0
Attacker Value
Unknown

CVE-2012-2437

Disclosure Date: November 26, 2012 (last updated October 05, 2023)
cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to generate arbitrary cookies via the name parameter in conjunction with the content parameter.
0
Attacker Value
Unknown

CVE-2012-2438

Disclosure Date: November 26, 2012 (last updated October 05, 2023)
ar web content manager (AWCM) 2.2 does not restrict the number of comment records that can be submitted through HTTP requests, which allows remote attackers to cause a denial of service (disk consumption) via the coment parameter to (1) show_video.php or (2) topic.php.
0
Attacker Value
Unknown

CVE-2011-2754

Disclosure Date: July 17, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the PageBuilder2 (aka Page Builder) theme in IBM WebSphere Portal 7.x before 7.0.0.1 CF006, as used in IBM Web Content Manager (WCM) and other products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2010-4810

Disclosure Date: July 08, 2011 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in AR Web Content Manager (AWCM) 2.1 final allow remote attackers to execute arbitrary PHP code via a URL in the theme_file parameter to (1) includes/window_top.php and (2) header.php, and the (3) lang_file parameter to control/common.php.
0