Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2024-6120
Disclosure Date: June 22, 2024 (last updated June 25, 2024)
The Sparkle Demo Importer plugin for WordPress is vulnerable to unauthorized database reset and demo data import due to a missing capability check on the multiple functions in all versions up to and including 1.4.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete all posts, pages, and uploaded files, as well as download and install a limited set of demo plugins.
0
Attacker Value
Unknown
CVE-2007-6541
Disclosure Date: December 27, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in neuron news 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the topic parameter in a viewtopic action, or the (2) newsyear or (3) newsmonth parameter in a newsarchive action to the default URI in patch/.
0
Attacker Value
Unknown
CVE-2007-6540
Disclosure Date: December 27, 2007 (last updated October 04, 2023)
SQL injection vulnerability in neuron news 1.0 allows remote attackers to execute arbitrary SQL commands via the q parameter to the default URI in patch/.
0
Attacker Value
Unknown
CVE-2007-5050
Disclosure Date: September 24, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in Neuron News 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the q parameter.
0