Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown

CVE-2020-19587

Disclosure Date: September 14, 2022 (last updated February 24, 2025)
Cross Site Scripting (XSS) vulnerability in configMap parameters in Yellowfin Business Intelligence 7.3 allows remote attackers to run arbitrary code via MIAdminStyles.i4 Admin UI.
Attacker Value
Unknown

CVE-2016-15002

Disclosure Date: June 09, 2022 (last updated February 23, 2025)
A vulnerability, which was classified as critical, was found in MONyog Ultimate 6.63. This affects an unknown part of the component Cookie Handler. The manipulation of the argument HasServerEdit/IsAdmin leads to privilege escalation. It is possible to initiate the attack remotely.
Attacker Value
Unknown

CVE-2021-38350

Disclosure Date: September 09, 2021 (last updated February 23, 2025)
The spideranalyse WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the date parameter found in the ~/analyse/index.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.0.1.
Attacker Value
Unknown

CVE-2019-10805

Disclosure Date: February 28, 2020 (last updated February 21, 2025)
valib through 2.0.0 allows Internal Property Tampering. A maliciously crafted JavaScript object can bypass several inspection functions provided by valib. Valib uses a built-in function (hasOwnProperty) from the unsafe user-input to examine an object. It is possible for a crafted payload to overwrite this function to manipulate the inspection results to bypass security checks.
Attacker Value
Unknown

CVE-2015-9263

Disclosure Date: August 27, 2018 (last updated November 27, 2024)
An issue was discovered in post2file.php in Up.Time Monitoring Station 7.5.0 (build 16) and 7.4.0 (build 13). It allows an attacker to upload an arbitrary file, such as a .php file that can execute arbitrary OS commands.
0
Attacker Value
Unknown

CVE-2017-11470

Disclosure Date: July 20, 2017 (last updated November 26, 2024)
IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatifGadget/getxenmetrics.php via the element parameter.
0
Attacker Value
Unknown

CVE-2017-11469

Disclosure Date: July 20, 2017 (last updated November 26, 2024)
get2post.php in IDERA Uptime Monitor 7.8 has directory traversal in the file_name parameter.
0
Attacker Value
Unknown

CVE-2017-11471

Disclosure Date: July 20, 2017 (last updated November 26, 2024)
IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatIfGadget/getmetrics.php via the element parameter.
0
Attacker Value
Unknown

CVE-2015-8268

Disclosure Date: June 10, 2016 (last updated November 25, 2024)
The up.time agent in Idera Uptime Infrastructure Monitor 7.5 and 7.6 on Linux allows remote attackers to read arbitrary files via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-2894

Disclosure Date: December 31, 2015 (last updated November 25, 2024)
Format string vulnerability in the up.time client in Idera Uptime Infrastructure Monitor 6.0 and 7.2 allows remote attackers to cause a denial of service (application crash) via format string specifiers.
0