Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown

CVE-2024-9442

Disclosure Date: November 21, 2024 (last updated January 05, 2025)
The F4 Improvements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
Attacker Value
Unknown

CVE-2023-4770

Disclosure Date: November 30, 2023 (last updated December 07, 2023)
An uncontrolled search path element vulnerability has been found on 4D and 4D server Windows executables applications, affecting version 19 R8 100218. This vulnerability consists in a DLL hijacking by replacing x64 shfolder.dll in the installation path, causing an arbitrary code execution.
Attacker Value
Unknown

CVE-2023-30223

Disclosure Date: June 16, 2023 (last updated October 08, 2023)
A broken authentication vulnerability in 4D SAS 4D Server software v17, v18, v19 R7, and earlier allows attackers to send crafted TCP packets containing requests to perform arbitrary actions.
Attacker Value
Unknown

CVE-2023-30222

Disclosure Date: June 16, 2023 (last updated October 08, 2023)
An information disclosure vulnerability in 4D SAS 4D Server Application v17, v18, v19 R7 and earlier allows attackers to retrieve password hashes for all users via eavesdropping.
Attacker Value
Unknown

CVE-2015-9424

Disclosure Date: September 26, 2019 (last updated November 27, 2024)
The multicons plugin before 3.0 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=multicons%2Fmulticons.php global_url or admin_url parameter.
Attacker Value
Unknown

CVE-2018-14796

Disclosure Date: September 20, 2018 (last updated November 27, 2024)
Tec4Data SmartCooler, all versions prior to firmware 180806, the device responds to a remote unauthenticated reboot command that may be used to perform a denial of service attack.
0
Attacker Value
Unknown

CVE-2008-6104

Disclosure Date: February 10, 2009 (last updated October 04, 2023)
SQL injection vulnerability in A4Desk PHP Event Calendar allows remote attackers to execute arbitrary SQL commands via the eventid parameter to admin/index.php.
0
Attacker Value
Unknown

CVE-2008-6103

Disclosure Date: February 10, 2009 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in index.php in A4Desk Event Calendar, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the v parameter.
0
Attacker Value
Unknown

CVE-2005-3143

Disclosure Date: October 05, 2005 (last updated October 04, 2023)
Unspecified vulnerability in the Mailbox Server for 4D WebStar before 5.3.5 allows attackers to cause a denial of service (crash) via IMAP clients on Mac OS X 10.4 Mail 2.
0
Attacker Value
Unknown

CVE-2005-1507

Disclosure Date: May 11, 2005 (last updated October 04, 2023)
Buffer overflow in the Tomcat plugin in 4d WebSTAR 5.33 and 5.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long URL.
0