Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown
CVE-2024-9442
Disclosure Date: November 21, 2024 (last updated January 05, 2025)
The F4 Improvements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
0
Attacker Value
Unknown
CVE-2023-4770
Disclosure Date: November 30, 2023 (last updated December 07, 2023)
An uncontrolled search path element vulnerability has been found on 4D and 4D server Windows executables applications, affecting version 19 R8 100218. This vulnerability consists in a DLL hijacking by replacing x64 shfolder.dll in the installation path, causing an arbitrary code execution.
0
Attacker Value
Unknown
CVE-2023-30223
Disclosure Date: June 16, 2023 (last updated October 08, 2023)
A broken authentication vulnerability in 4D SAS 4D Server software v17, v18, v19 R7, and earlier allows attackers to send crafted TCP packets containing requests to perform arbitrary actions.
0
Attacker Value
Unknown
CVE-2023-30222
Disclosure Date: June 16, 2023 (last updated October 08, 2023)
An information disclosure vulnerability in 4D SAS 4D Server Application v17, v18, v19 R7 and earlier allows attackers to retrieve password hashes for all users via eavesdropping.
0
Attacker Value
Unknown
CVE-2015-9424
Disclosure Date: September 26, 2019 (last updated November 27, 2024)
The multicons plugin before 3.0 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=multicons%2Fmulticons.php global_url or admin_url parameter.
0
Attacker Value
Unknown
CVE-2018-14796
Disclosure Date: September 20, 2018 (last updated November 27, 2024)
Tec4Data SmartCooler, all versions prior to firmware 180806, the device responds to a remote unauthenticated reboot command that may be used to perform a denial of service attack.
0
Attacker Value
Unknown
CVE-2008-6104
Disclosure Date: February 10, 2009 (last updated October 04, 2023)
SQL injection vulnerability in A4Desk PHP Event Calendar allows remote attackers to execute arbitrary SQL commands via the eventid parameter to admin/index.php.
0
Attacker Value
Unknown
CVE-2008-6103
Disclosure Date: February 10, 2009 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in index.php in A4Desk Event Calendar, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the v parameter.
0
Attacker Value
Unknown
CVE-2005-3143
Disclosure Date: October 05, 2005 (last updated October 04, 2023)
Unspecified vulnerability in the Mailbox Server for 4D WebStar before 5.3.5 allows attackers to cause a denial of service (crash) via IMAP clients on Mac OS X 10.4 Mail 2.
0
Attacker Value
Unknown
CVE-2005-1507
Disclosure Date: May 11, 2005 (last updated October 04, 2023)
Buffer overflow in the Tomcat plugin in 4d WebSTAR 5.33 and 5.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long URL.
0