Show filters
86 Total Results
Displaying 1-10 of 86
Sort by:
Attacker Value
Unknown
CVE-2022-0879
Disclosure Date: April 18, 2022 (last updated October 07, 2023)
The Caldera Forms WordPress plugin before 1.9.7 does not validate and escape the cf-api parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting
0
Attacker Value
Unknown
CVE-2021-24896
Disclosure Date: December 13, 2021 (last updated October 07, 2023)
The Caldera Forms WordPress plugin before 1.9.5 does not sanitise and escape the Form Name before outputting it in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
0
Attacker Value
Unknown
CVE-2018-7747
Disclosure Date: April 20, 2018 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin before 1.6.0-rc.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a greeting message, (2) the email transaction log, or (3) an imported form.
0
Attacker Value
Unknown
CVE-2014-2936
Disclosure Date: May 08, 2014 (last updated October 05, 2023)
The directory manager in Caldera 9.20 allows remote attackers to conduct variable-injection attacks in the global scope via (1) the maindir_hotfolder parameter to dirmng/index.php, or an unspecified parameter to (2) PPD/index.php, (3) dirmng/docmd.php, or (4) dirmng/param.php.
0
Attacker Value
Unknown
CVE-2014-2934
Disclosure Date: May 08, 2014 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in Caldera 9.20 allow remote attackers to execute arbitrary SQL commands via the tr parameter to (1) costview2/jobs.php or (2) costview2/printers.php.
0
Attacker Value
Unknown
CVE-2014-2935
Disclosure Date: May 08, 2014 (last updated October 05, 2023)
costview3/xmlrpc_server/xmlrpc.php in CostView in Caldera 9.20 allows remote attackers to execute arbitrary commands via shell metacharacters in a methodCall element in a PHP XMLRPC request.
0
Attacker Value
Unknown
CVE-2014-2933
Disclosure Date: May 08, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in dirmng/index.php in Caldera 9.20 allows remote attackers to access arbitrary directories via a crafted pathname.
0
Attacker Value
Unknown
CVE-2007-0759
Disclosure Date: February 06, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in EasyMoblog 0.5.1 allow remote attackers to execute arbitrary SQL commands via the (1) i or (2) post_id parameter to add_comment.php, which triggers an injection in libraries.inc.php; or (3) the i parameter to list_comments.php, which triggers an injection in libraries.inc.php.
0
Attacker Value
Unknown
CVE-2003-0658
Disclosure Date: October 20, 2003 (last updated February 22, 2025)
Docview before 1.1-18 in Caldera OpenLinux 3.1.1, SCO Linux 4.0, OpenServer 5.0.7, configures the Apache web server in a way that allows remote attackers to read arbitrary publicly readable files via a certain URL, possibly related to rewrite rules.
0
Attacker Value
Unknown
CVE-2002-1231
Disclosure Date: November 04, 2002 (last updated February 22, 2025)
SCO UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to cause a denial of service via an rcp call on /proc.
0