Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2016-10559

Disclosure Date: May 29, 2018 (last updated November 26, 2024)
selenium-download downloads the latest versions of the selenium standalone server and the chromedriver. selenium-download before 2.0.7 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.
0
Attacker Value
Unknown

CVE-2018-6868

Disclosure Date: February 23, 2018 (last updated November 26, 2024)
Cross Site Scripting (XSS) exists in PHP Scripts Mall Slickdeals / DealNews / Groupon Clone Script 3.0.2 via a User Profile Field parameter.
0
Attacker Value
Unknown

CVE-2017-17638

Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.
0
Attacker Value
Unknown

CVE-2017-17575

Disclosure Date: December 13, 2017 (last updated November 26, 2024)
FS Groupon Clone 1.0 has SQL Injection via the item_details.php id parameter or the vendor_details.php id parameter.
Attacker Value
Unknown

CVE-2012-5809

Disclosure Date: November 04, 2012 (last updated October 05, 2023)
The Groupon Redemptions application for Android does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
0