Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

CVE-2024-6497

Disclosure Date: July 20, 2024 (last updated January 05, 2025)
The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 12.3.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown

CVE-2023-6806

Disclosure Date: February 29, 2024 (last updated February 29, 2024)
The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Job Settings user profile fields in all versions up to, and including, 3.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown

CVE-2022-46858

Disclosure Date: May 09, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Amin A.Rezapour Product Specifications for Woocommerce plugin <= 0.6.0 versions.
Attacker Value
Unknown

CVE-2014-7720

Disclosure Date: October 21, 2014 (last updated October 05, 2023)
The Better Homes and Gardens Aus (aka com.pacificmagazines.betterhomesandgardens) application @7F0801B2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2010-2111

Disclosure Date: May 28, 2010 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in user/user-set.do in Pacific Timesheet 6.74 build 363 allows remote attackers to hijack the authentication of administrators for requests that create a new administrator via a new_admin action.
0
Attacker Value
Unknown

CVE-2002-0683

Disclosure Date: July 23, 2002 (last updated February 22, 2025)
Directory traversal vulnerability in Carello 1.3 allows remote attackers to execute programs on the server via a .. (dot dot) in the VBEXE parameter.
0
Attacker Value
Unknown

CVE-2000-0396

Disclosure Date: May 24, 2000 (last updated February 22, 2025)
The add.exe program in the Carello shopping cart software allows remote attackers to duplicate files on the server, which could allow the attacker to read source code for web scripts such as .ASP files.
0
Attacker Value
Unknown

CVE-1999-0915

Disclosure Date: October 28, 1999 (last updated February 22, 2025)
URL Live! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.
0