Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2021-24867

Disclosure Date: February 21, 2022 (last updated February 23, 2025)
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
Attacker Value
Unknown

CVE-2009-1505

Disclosure Date: May 01, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the News Page module 5.x before 5.x-1.2 for Drupal allows remote authenticated users, with News Page nodes create and edit privileges, to execute arbitrary SQL commands via the Include Words (aka keywords) field.
0
Attacker Value
Unknown

CVE-2002-1656

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
X-News (x_news) 1.1 and earlier allows attackers to authenticate as other users by obtaining the MD5 checksum of the password, e.g. via sniffing or the users.txt data file, and providing it in a cookie.
0
Attacker Value
Unknown

CVE-2002-2046

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
x_news.php in X-News (x_news) 1.1 and earlier allows remote attackers to gain administrative privileges by stealing and replaying the md5_password cookie.
0
Attacker Value
Unknown

CVE-1999-0868

Disclosure Date: February 20, 1997 (last updated February 22, 2025)
ucbmail allows remote attackers to execute commands via shell metacharacters that are passed to it from INN.
0
Attacker Value
Unknown

CVE-1999-0043

Disclosure Date: December 04, 1996 (last updated February 22, 2025)
Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.
0