Show filters
86 Total Results
Displaying 1-10 of 86
Sort by:
Attacker Value
Unknown

CVE-2022-0879

Disclosure Date: April 18, 2022 (last updated October 07, 2023)
The Caldera Forms WordPress plugin before 1.9.7 does not validate and escape the cf-api parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting
Attacker Value
Unknown

CVE-2021-24896

Disclosure Date: December 13, 2021 (last updated October 07, 2023)
The Caldera Forms WordPress plugin before 1.9.5 does not sanitise and escape the Form Name before outputting it in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Attacker Value
Unknown

CVE-2018-7747

Disclosure Date: April 20, 2018 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin before 1.6.0-rc.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a greeting message, (2) the email transaction log, or (3) an imported form.
0
Attacker Value
Unknown

CVE-2014-2936

Disclosure Date: May 08, 2014 (last updated October 05, 2023)
The directory manager in Caldera 9.20 allows remote attackers to conduct variable-injection attacks in the global scope via (1) the maindir_hotfolder parameter to dirmng/index.php, or an unspecified parameter to (2) PPD/index.php, (3) dirmng/docmd.php, or (4) dirmng/param.php.
0
Attacker Value
Unknown

CVE-2014-2934

Disclosure Date: May 08, 2014 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in Caldera 9.20 allow remote attackers to execute arbitrary SQL commands via the tr parameter to (1) costview2/jobs.php or (2) costview2/printers.php.
0
Attacker Value
Unknown

CVE-2014-2935

Disclosure Date: May 08, 2014 (last updated October 05, 2023)
costview3/xmlrpc_server/xmlrpc.php in CostView in Caldera 9.20 allows remote attackers to execute arbitrary commands via shell metacharacters in a methodCall element in a PHP XMLRPC request.
0
Attacker Value
Unknown

CVE-2014-2933

Disclosure Date: May 08, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in dirmng/index.php in Caldera 9.20 allows remote attackers to access arbitrary directories via a crafted pathname.
0
Attacker Value
Unknown

CVE-2007-0759

Disclosure Date: February 06, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in EasyMoblog 0.5.1 allow remote attackers to execute arbitrary SQL commands via the (1) i or (2) post_id parameter to add_comment.php, which triggers an injection in libraries.inc.php; or (3) the i parameter to list_comments.php, which triggers an injection in libraries.inc.php.
0
Attacker Value
Unknown

CVE-2003-0658

Disclosure Date: October 20, 2003 (last updated February 22, 2025)
Docview before 1.1-18 in Caldera OpenLinux 3.1.1, SCO Linux 4.0, OpenServer 5.0.7, configures the Apache web server in a way that allows remote attackers to read arbitrary publicly readable files via a certain URL, possibly related to rewrite rules.
0
Attacker Value
Unknown

CVE-2002-1231

Disclosure Date: November 04, 2002 (last updated February 22, 2025)
SCO UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to cause a denial of service via an rcp call on /proc.
0