Количество 314 458
Количество 314 458
GHSA-2hwp-jrpr-6f78
The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encrypted sites are only sent via SSL encrypted sessions to the site, which allows a remote attacker to cause a cached password to be sent in cleartext to a spoofed site.
GHSA-2hwp-g4g7-mwwj
Reflected Cross-Site Scripting in jquery.terminal
GHSA-2hwp-cw9h-92vp
Multiple cross-site scripting (XSS) vulnerabilities in the web interface in Aruba Mobility Controller 2.4.8.x-FIPS, 2.5.5.x, 2.5.6.x, 3.1.1.x, 3.2.0.x, and 3.3.1.x allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
GHSA-2hwp-94gx-j73f
app/Model/Attribute.php in MISP before 2.4.198 ignores an ACL during a GUI attribute search.
GHSA-2hwp-78q9-9xwc
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Unfoldwp Magazine Elite allows PHP Local File Inclusion. This issue affects Magazine Elite: from n/a through 1.2.4.
GHSA-2hwm-f3wp-3rq5
A “CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')” allows malicious users to permanently inject arbitrary Javascript code.
GHSA-2hwm-966r-8hqw
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the AFParseDateEx method. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-7453.
GHSA-2hwm-6xjf-3xmx
Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling
GHSA-2hwm-56x6-pwwc
Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.
GHSA-2hwj-v42x-jfwh
Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/manage_website.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
GHSA-2hwf-vrcf-2q7m
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor allows Stored XSS.This issue affects Post and Page Builder by BoldGrid – Visual Drag and Drop Editor: from n/a through 1.27.4.
GHSA-2hwf-hm8p-fc5c
A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attackers to arbitrarily change the Administrator password and escalate privileges.
GHSA-2hwf-2vrp-g37h
The mintToken function of a smart contract implementation for tickets (TKT), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
GHSA-2hw9-m765-6g54
CVE was unused by HPE.
GHSA-2hw9-c84h-m727
In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112856493
GHSA-2hw8-qj3h-c7pq
badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, which allows remote attackers to conduct PHP object injection attacks via unspecified vectors, as demonstrated by overwriting the value of the userid parameter.
GHSA-2hw7-w5mq-h4q7
Biometric Shift Employee Management System has XSS via the criteria parameter in an index.php?user=competency_criteria request.
GHSA-2hw7-mxvj-m455
Path traversal in Node-RED-Dashboard
GHSA-2hw7-5qc9-q2cg
Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg.
GHSA-2hw7-485w-9j23
WHMCompleteSolution (WHMCS) before 2.3 assigns incorrect permissions to "resellers", which allows remote authenticated users to perform privileged actions or obtain sensitive information. NOTE: this report is based on a vendor bug report that identified "incorrect permissions." However, the vendor did not label it a security issue, and there was no statement regarding whether or not the permissions were actually more permissive than intended. If in fact the permissions were more restrictive than intended, then this would be a functional problem but not a vulnerability.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2hwp-jrpr-6f78 The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encrypted sites are only sent via SSL encrypted sessions to the site, which allows a remote attacker to cause a cached password to be sent in cleartext to a spoofed site. | 1% Низкий | почти 4 года назад | ||
GHSA-2hwp-g4g7-mwwj Reflected Cross-Site Scripting in jquery.terminal | больше 6 лет назад | |||
GHSA-2hwp-cw9h-92vp Multiple cross-site scripting (XSS) vulnerabilities in the web interface in Aruba Mobility Controller 2.4.8.x-FIPS, 2.5.5.x, 2.5.6.x, 3.1.1.x, 3.2.0.x, and 3.3.1.x allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 0% Низкий | почти 4 года назад | ||
GHSA-2hwp-94gx-j73f app/Model/Attribute.php in MISP before 2.4.198 ignores an ACL during a GUI attribute search. | CVSS3: 4.3 | 0% Низкий | 12 месяцев назад | |
GHSA-2hwp-78q9-9xwc Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Unfoldwp Magazine Elite allows PHP Local File Inclusion. This issue affects Magazine Elite: from n/a through 1.2.4. | CVSS3: 8.1 | 0% Низкий | 5 месяцев назад | |
GHSA-2hwm-f3wp-3rq5 A “CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')” allows malicious users to permanently inject arbitrary Javascript code. | CVSS3: 7.7 | 0% Низкий | больше 1 года назад | |
GHSA-2hwm-966r-8hqw This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the AFParseDateEx method. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-7453. | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
GHSA-2hwm-6xjf-3xmx Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling | CVSS3: 9.8 | 32% Средний | почти 4 года назад | |
GHSA-2hwm-56x6-pwwc Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. | около 1 месяца назад | |||
GHSA-2hwj-v42x-jfwh Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/manage_website.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | CVSS3: 7.2 | 0% Низкий | больше 3 лет назад | |
GHSA-2hwf-vrcf-2q7m Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor allows Stored XSS.This issue affects Post and Page Builder by BoldGrid – Visual Drag and Drop Editor: from n/a through 1.27.4. | CVSS3: 6.5 | 0% Низкий | около 1 года назад | |
GHSA-2hwf-hm8p-fc5c A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attackers to arbitrarily change the Administrator password and escalate privileges. | CVSS3: 7.5 | 0% Низкий | больше 1 года назад | |
GHSA-2hwf-2vrp-g37h The mintToken function of a smart contract implementation for tickets (TKT), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-2hw9-m765-6g54 CVE was unused by HPE. | около 3 лет назад | |||
GHSA-2hw9-c84h-m727 In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112856493 | 0% Низкий | больше 3 лет назад | ||
GHSA-2hw8-qj3h-c7pq badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, which allows remote attackers to conduct PHP object injection attacks via unspecified vectors, as demonstrated by overwriting the value of the userid parameter. | 1% Низкий | больше 3 лет назад | ||
GHSA-2hw7-w5mq-h4q7 Biometric Shift Employee Management System has XSS via the criteria parameter in an index.php?user=competency_criteria request. | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-2hw7-mxvj-m455 Path traversal in Node-RED-Dashboard | 92% Критический | около 5 лет назад | ||
GHSA-2hw7-5qc9-q2cg Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg. | 2% Низкий | почти 4 года назад | ||
GHSA-2hw7-485w-9j23 WHMCompleteSolution (WHMCS) before 2.3 assigns incorrect permissions to "resellers", which allows remote authenticated users to perform privileged actions or obtain sensitive information. NOTE: this report is based on a vendor bug report that identified "incorrect permissions." However, the vendor did not label it a security issue, and there was no statement regarding whether or not the permissions were actually more permissive than intended. If in fact the permissions were more restrictive than intended, then this would be a functional problem but not a vulnerability. | 0% Низкий | почти 4 года назад |
Уязвимостей на страницу