Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2024-6295
Disclosure Date: June 25, 2024 (last updated January 05, 2025)
udn News Android APP stores the unencrypted user session in the local database when user log into the application. A malicious APP or an attacker with physical access to the Android device can retrieve this session and use it to log into the news APP and other services provided by udn.
0
Attacker Value
Unknown
CVE-2024-6294
Disclosure Date: June 25, 2024 (last updated January 05, 2025)
udn News Android APP stores the user session in logcat file when user log into the APP. A malicious APP or an attacker with physical access to the Android device can retrieve this session and use it to log into the news APP and other services provided by udn.
0
Attacker Value
Unknown
CVE-2023-51699
Disclosure Date: March 15, 2024 (last updated April 01, 2024)
Fluid is an open source Kubernetes-native Distributed Dataset Orchestrator and Accelerator for data-intensive applications. An OS command injection vulnerability within the Fluid project's JuicefsRuntime can potentially allow an authenticated user, who has the authority to create or update the K8s CRD Dataset/JuicefsRuntime, to execute arbitrary OS commands within the juicefs related containers. This could lead to unauthorized access, modification or deletion of data. Users who're using versions < 0.9.3 with JuicefsRuntime should upgrade to v0.9.3.
0
Attacker Value
Unknown
CVE-2023-46643
Disclosure Date: November 08, 2023 (last updated November 16, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GARY JEZORSKI CloudNet360 plugin <= 3.2.0 versions.
0
Attacker Value
Unknown
CVE-2006-4327
Disclosure Date: August 24, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in add_url.php in CloudNine Interactive Links Manager 2006-06-12 allow remote attackers to inject arbitrary web script or HTML via the (1) title, (2) description, or (3) keywords parameters.
0
Attacker Value
Unknown
CVE-2006-4328
Disclosure Date: August 24, 2006 (last updated October 04, 2023)
SQL injection vulnerability in admin.php in CloudNine Interactive Links Manager 2006-06-12, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the nick parameter.
0