Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2022-41404
Disclosure Date: October 11, 2022 (last updated October 08, 2023)
An issue in the fetch() method in the BasicProfile class of org.ini4j before v0.5.4 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
0
Attacker Value
Unknown
CVE-2018-19527
Disclosure Date: November 29, 2018 (last updated November 27, 2024)
i4 assistant 7.85 allows XSS via a crafted machine name field within iOS settings.
0
Attacker Value
Unknown
CVE-2018-17090
Disclosure Date: September 16, 2018 (last updated November 27, 2024)
An issue was discovered in DonLinkage 6.6.8. The modules /pages/bazy/bazy_adresow.php and /pages/proxy/add.php are vulnerable to stored XSS that can be triggered by closing <textarea> followed by <script></script> tags.
0
Attacker Value
Unknown
CVE-2018-17092
Disclosure Date: September 16, 2018 (last updated November 27, 2024)
An issue was discovered in DonLinkage 6.6.8. SQL injection in /pages/proxy/php.php and /pages/proxy/add.php can be exploited via specially crafted input, allowing an attacker to obtain information from a database. The vulnerability can only be triggered by an authorized user.
0
Attacker Value
Unknown
CVE-2018-17091
Disclosure Date: September 16, 2018 (last updated November 27, 2024)
An issue was discovered in DonLinkage 6.6.8. It allows remote attackers to obtain potentially sensitive information via a direct request for files/temporary.txt.
0
Attacker Value
Unknown
CVE-2015-1445
Disclosure Date: August 28, 2017 (last updated November 26, 2024)
HTTP header injection in the httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30.
0
Attacker Value
Unknown
CVE-2015-1443
Disclosure Date: August 28, 2017 (last updated November 26, 2024)
The httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30 allows remote attackers to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2015-1444
Disclosure Date: February 06, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the web administration frontend in the httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30 allow remote attackers to inject arbitrary web script or HTML via the (1) conntrack.cgi, (2) index.cgi, (3) log_syslog.cgi, (4) problems.cgi, (5) status.cgi, (6) status_network.cgi, or (7) status_system.cgi script in admin/.
0
Attacker Value
Unknown
CVE-2014-7522
Disclosure Date: October 20, 2014 (last updated October 05, 2023)
The Maccabi Pakal (aka com.ideomobile.pakalmaccabi) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0