Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2024-6295

Disclosure Date: June 25, 2024 (last updated January 05, 2025)
udn News Android APP stores the unencrypted user session in the local database when user log into the application. A malicious APP or an attacker with physical access to the Android device can retrieve this session and use it to log into the news APP and other services provided by udn.
0
Attacker Value
Unknown

CVE-2024-6294

Disclosure Date: June 25, 2024 (last updated January 05, 2025)
udn News Android APP stores the user session in logcat file when user log into the APP. A malicious APP or an attacker with physical access to the Android device can retrieve this session and use it to log into the news APP and other services provided by udn.
0
Attacker Value
Unknown

CVE-2023-51699

Disclosure Date: March 15, 2024 (last updated April 01, 2024)
Fluid is an open source Kubernetes-native Distributed Dataset Orchestrator and Accelerator for data-intensive applications. An OS command injection vulnerability within the Fluid project's JuicefsRuntime can potentially allow an authenticated user, who has the authority to create or update the K8s CRD Dataset/JuicefsRuntime, to execute arbitrary OS commands within the juicefs related containers. This could lead to unauthorized access, modification or deletion of data. Users who're using versions < 0.9.3 with JuicefsRuntime should upgrade to v0.9.3.
0
Attacker Value
Unknown

CVE-2023-46643

Disclosure Date: November 08, 2023 (last updated November 16, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GARY JEZORSKI CloudNet360 plugin <= 3.2.0 versions.
Attacker Value
Unknown

CVE-2006-4327

Disclosure Date: August 24, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in add_url.php in CloudNine Interactive Links Manager 2006-06-12 allow remote attackers to inject arbitrary web script or HTML via the (1) title, (2) description, or (3) keywords parameters.
0
Attacker Value
Unknown

CVE-2006-4328

Disclosure Date: August 24, 2006 (last updated October 04, 2023)
SQL injection vulnerability in admin.php in CloudNine Interactive Links Manager 2006-06-12, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the nick parameter.
0