Show filters
20 Total Results
Displaying 1-10 of 20
Sort by:
Attacker Value
Unknown

CVE-2024-49260

Disclosure Date: October 16, 2024 (last updated October 17, 2024)
Unrestricted Upload of File with Dangerous Type vulnerability in Limb WordPress Gallery Plugin – Limb Image Gallery allows Code Injection.This issue affects WordPress Gallery Plugin – Limb Image Gallery: from n/a through 1.5.7.
0
Attacker Value
Unknown

CVE-2024-49258

Disclosure Date: October 16, 2024 (last updated October 17, 2024)
Path Traversal: '.../...//' vulnerability in Limb WordPress Gallery Plugin – Limb Image Gallery.This issue affects WordPress Gallery Plugin – Limb Image Gallery: from n/a through 1.5.7.
0
Attacker Value
Unknown

CVE-2022-4974

Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Attacker Value
Unknown

CVE-2022-28454

Disclosure Date: April 28, 2022 (last updated October 07, 2023)
Limbas 4.3.36.1319 is vulnerable to Cross Site Scripting (XSS).
Attacker Value
Unknown

CVE-2019-14790

Disclosure Date: August 15, 2019 (last updated November 27, 2024)
The limb-gallery (aka Limb Gallery) plugin 1.4.0 for WordPress has XSS via the wp-admin/admin-ajax.php?action=grsGalleryAjax&grsAction=shortcode task parameter,
0
Attacker Value
Unknown

CVE-2016-10674

Disclosure Date: May 29, 2018 (last updated November 26, 2024)
limbus-buildgen is a "build anywhere" build system. limbus-buildgen versions below 0.1.1 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.
0
Attacker Value
Unknown

CVE-2008-6078

Disclosure Date: February 06, 2009 (last updated October 04, 2023)
SQL injection vulnerability in open.php in the Private Messaging (com_privmsg) component for Limbo CMS allows remote attackers to execute arbitrary SQL commands via the id parameter in a pms action to index.php.
0
Attacker Value
Unknown

CVE-2008-0734

Disclosure Date: February 13, 2008 (last updated October 04, 2023)
SQL injection vulnerability in class_auth.php in Limbo CMS 1.0.4.2, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the cuid cookie parameter to admin.php.
0
Attacker Value
Unknown

CVE-2007-6564

Disclosure Date: December 28, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in admin.php in Limbo CMS 1.0.4.2 allows remote attackers to inject arbitrary web script or HTML via the com_option parameter.
0
Attacker Value
Unknown

CVE-2007-2000

Disclosure Date: April 12, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in admin/admin.php in Crea-Book 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) pseudo or (2) passe parameter.
0