Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2024-6497
Disclosure Date: July 20, 2024 (last updated January 05, 2025)
The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 12.3.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2023-6806
Disclosure Date: February 29, 2024 (last updated February 29, 2024)
The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Job Settings user profile fields in all versions up to, and including, 3.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2022-46858
Disclosure Date: May 09, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Amin A.Rezapour Product Specifications for Woocommerce plugin <= 0.6.0 versions.
0
Attacker Value
Unknown
CVE-2014-7720
Disclosure Date: October 21, 2014 (last updated October 05, 2023)
The Better Homes and Gardens Aus (aka com.pacificmagazines.betterhomesandgardens) application @7F0801B2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2010-2111
Disclosure Date: May 28, 2010 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in user/user-set.do in Pacific Timesheet 6.74 build 363 allows remote attackers to hijack the authentication of administrators for requests that create a new administrator via a new_admin action.
0
Attacker Value
Unknown
CVE-2002-0683
Disclosure Date: July 23, 2002 (last updated February 22, 2025)
Directory traversal vulnerability in Carello 1.3 allows remote attackers to execute programs on the server via a .. (dot dot) in the VBEXE parameter.
0
Attacker Value
Unknown
CVE-2000-0396
Disclosure Date: May 24, 2000 (last updated February 22, 2025)
The add.exe program in the Carello shopping cart software allows remote attackers to duplicate files on the server, which could allow the attacker to read source code for web scripts such as .ASP files.
0
Attacker Value
Unknown
CVE-1999-0915
Disclosure Date: October 28, 1999 (last updated February 22, 2025)
URL Live! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.
0