Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown
CVE-2024-35715
Disclosure Date: June 08, 2024 (last updated September 18, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in peregrinethemes Bloglo, peregrinethemes Blogvi allows Stored XSS.This issue affects Bloglo: from n/a through 1.1.3; Blogvi: from n/a through 1.0.5.
0
Attacker Value
Unknown
CVE-2015-10097
Disclosure Date: March 25, 2023 (last updated October 20, 2023)
A vulnerability was found in grinnellplans-php up to 3.0. It has been declared as critical. Affected by this vulnerability is the function interface_disp_page/interface_disp_page of the file read.php. The manipulation leads to sql injection. The attack can be launched remotely. The identifier of the patch is 57e4409e19203a94495140ff1b5a697734d17cfb. It is recommended to apply a patch to fix this issue. The identifier VDB-223801 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2020-15899
Disclosure Date: July 28, 2020 (last updated February 21, 2025)
Grin 3.0.0 before 4.0.0 has insufficient validation of data related to Mimblewimble.
0
Attacker Value
Unknown
CVE-2020-12439
Disclosure Date: May 05, 2020 (last updated February 21, 2025)
Grin before 3.1.0 allows attackers to adversely affect availability of data on a Mimblewimble blockchain.
0
Attacker Value
Unknown
CVE-2020-6638
Disclosure Date: January 21, 2020 (last updated February 21, 2025)
Grin through 2.1.1 has Insufficient Validation.
0
Attacker Value
Unknown
CVE-2019-9195
Disclosure Date: February 26, 2019 (last updated November 27, 2024)
util/src/zip.rs in Grin before 1.0.2 mishandles suspicious files. An attacker can execute arbitrary code via directory traversal in a ZIP archive.
0
Attacker Value
Unknown
CVE-2018-12909
Disclosure Date: June 27, 2018 (last updated November 08, 2023)
Webgrind 1.5 relies on user input to display a file, which lets anyone view files from the local filesystem (that the webserver user has access to) via an index.php?op=fileviewer&file= URI. NOTE: the vendor indicates that the product is not intended for a "publicly accessible environment.
0
Attacker Value
Unknown
CVE-2010-5260
Disclosure Date: September 07, 2012 (last updated October 05, 2023)
Untrusted search path vulnerability in Agrin All DVD Ripper 4.0 allows local users to gain privileges via a Trojan horse wnaspi32.dll file in the current working directory, as demonstrated by a directory that contains a .ifo file. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2012-1790
Disclosure Date: March 19, 2012 (last updated October 04, 2023)
Absolute path traversal vulnerability in Webgrind 1.0 and 1.0.2 allows remote attackers to read arbitrary files via a full pathname in the file parameter to index.php.
0
Attacker Value
Unknown
CVE-2009-4622
Disclosure Date: January 18, 2010 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in admin/admin_news_bot.php in Drunken:Golem Gaming Portal 0.5.1 alpha 2 allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter, a different vector than CVE-2007-0572.
0