Aggregator
CVE-2005-2246 | PhotoAlbum 1.1 getpage.php set_menu memory corruption (EDB-3596 / BID-23189)
5 months 1 week ago
A vulnerability has been found in PhotoAlbum 1.1 and classified as critical. Affected by this vulnerability is an unknown functionality in the library lib/static/header.php of the file getpage.php. The manipulation of the argument set_menu leads to memory corruption.
This vulnerability is known as CVE-2005-2246. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2014-5778 | Pou 1.4.53 X.509 Certificate cryptographic issues (VU#582497)
5 months 1 week ago
A vulnerability was found in Pou 1.4.53. It has been classified as critical. This affects an unknown part of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is uniquely identified as CVE-2014-5778. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2008-5889 | Icash Click/Rank user.asp action cross site scripting (EDB-7486 / BID-32855)
5 months 1 week ago
A vulnerability classified as problematic has been found in Icash Click and Rank. Affected is an unknown function of the file user.asp. The manipulation of the argument action leads to cross site scripting.
This vulnerability is traded as CVE-2008-5889. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2015-2673 | WP EasyCart Plugin up to 3.0.20 on WordPress admin_ajax_functions.php ec_ajax_update_option/ec_ajax_clear_all_taxrates option_name/option_value access control
5 months 1 week ago
A vulnerability was found in WP EasyCart Plugin up to 3.0.20 on WordPress and classified as critical. Affected by this issue is the function ec_ajax_update_option/ec_ajax_clear_all_taxrates of the file inc/admin/admin_ajax_functions.php. The manipulation of the argument option_name/option_value as part of Parameter leads to improper access controls.
This vulnerability is handled as CVE-2015-2673. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2014-8499 | Zoho ManageEngine Password Manager Pro up to 7.0 SQLAdvancedALSearchResult.cc SEARCH_ALL sql injection (Exploit 129036 / EDB-35210)
5 months 1 week ago
A vulnerability, which was classified as critical, has been found in Zoho ManageEngine Password Manager Pro up to 7.0. This issue affects some unknown processing of the file SQLAdvancedALSearchResult.cc. The manipulation of the argument SEARCH_ALL leads to sql injection.
The identification of this vulnerability is CVE-2014-8499. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2018-19207 | Van Ons WP GDPR Compliance Plugin up to 1.4.2 on WordPress $wpdb->prepare direct request (Nessus ID 118935 / ID 154025)
5 months 1 week ago
A vulnerability was found in Van Ons WP GDPR Compliance Plugin up to 1.4.2 on WordPress. It has been classified as critical. Affected is the function $wpdb->prepare. The manipulation leads to direct request.
This vulnerability is traded as CVE-2018-19207. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-32706 | Pi-hole up to 5.5.0 Web Interface preg_match code injection
5 months 1 week ago
A vulnerability was found in Pi-hole up to 5.5.0. It has been rated as critical. Affected by this issue is the function preg_match of the component Web Interface Handler. The manipulation leads to code injection.
This vulnerability is handled as CVE-2021-32706. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-5259 | Cambium cnPilot 4.3.2-R4 /adm/syscmd.asp Hostname 7pk security
5 months 1 week ago
A vulnerability classified as critical was found in Cambium cnPilot 4.3.2-R4. This vulnerability affects unknown code of the file /adm/syscmd.asp. The manipulation as part of Hostname leads to 7pk security features.
This vulnerability was named CVE-2017-5259. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2012-4940 | Gecad Axigen Free Mail Server fileName path traversal (VU#586556 / ID 122590)
5 months 1 week ago
A vulnerability was found in Gecad Axigen Free Mail Server. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument fileName leads to path traversal.
This vulnerability is known as CVE-2012-4940. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2014-7862 | Zoho ManageEngine Desktop Central/Desktop Central MSP 10.1.2137.2 DCPluginServelet Servlet addPlugInUser Account access control (ID 129769 / EDB-43892)
5 months 1 week ago
A vulnerability was found in Zoho ManageEngine Desktop Central and Desktop Central MSP 10.1.2137.2. It has been declared as critical. This vulnerability affects the function addPlugInUser of the component DCPluginServelet Servlet. The manipulation leads to improper access controls (Account).
This vulnerability was named CVE-2014-7862. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2016-6601 | Zoho WebNMS Framework 5.2/5.2 SP1 servlets/FetchFile fileName path traversal (EDB-40229 / ID 11686)
5 months 1 week ago
A vulnerability was found in Zoho WebNMS Framework 5.2/5.2 SP1. It has been rated as critical. This issue affects some unknown processing of the file servlets/FetchFile. The manipulation of the argument fileName leads to path traversal.
The identification of this vulnerability is CVE-2016-6601. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2010-2731 | Microsoft IIS 5.1 Access Restriction improper authentication (MS10-065 / Nessus ID 47594)
5 months 1 week ago
A vulnerability was found in Microsoft IIS 5.1. It has been rated as critical. This issue affects some unknown processing of the component Access Restriction. The manipulation leads to improper authentication.
The identification of this vulnerability is CVE-2010-2731. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2013-6129 | vBulletin 4.1/5.0.0 access control (SBV-42218 / BID-62909)
5 months 1 week ago
A vulnerability was found in vBulletin 4.1/5.0.0 and classified as critical. This issue affects some unknown processing. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2013-6129. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2017-7615 | MantisBT up to 2.3.0 verify.php confirm_hash password recovery (ID 159219 / EDB-41890)
5 months 1 week ago
A vulnerability was found in MantisBT up to 2.3.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file verify.php. The manipulation of the argument confirm_hash leads to weak password recovery.
This vulnerability is known as CVE-2017-7615. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2014-5777 | CocoPPa icon wallpaper dressup-CocoPPa 2.8.4 X.509 Certificate cryptographic issues (VU#582497)
5 months 1 week ago
A vulnerability was found in CocoPPa icon wallpaper dressup-CocoPPa 2.8.4 and classified as critical. Affected by this issue is some unknown functionality of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is handled as CVE-2014-5777. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2002-1125 | FreeBSD 4.2/4.3/4.4/4.5/4.6 File Descriptors wmnet2 Memory information disclosure (EDB-21798 / XFDB-10109)
5 months 1 week ago
A vulnerability classified as problematic was found in FreeBSD 4.2/4.3/4.4/4.5/4.6. This vulnerability affects unknown code of the file asmon/ascpu/bubblemon/wmmon/wmnet2 of the component File Descriptors. The manipulation leads to information disclosure (Memory).
This vulnerability was named CVE-2002-1125. Local access is required to approach this attack. Furthermore, there is an exploit available.
vuldb.com
FAA已批准猎鹰9号火箭可以重新发射 但之前23手火箭爆炸还需要调查
5 months 1 week ago
CVE-2007-1735 | Corel WordPerfect 13.0.0.565 Core memory corruption (EDB-3593 / XFDB-33286)
5 months 1 week ago
A vulnerability was found in Corel WordPerfect 13.0.0.565. It has been classified as very critical. This affects an unknown part of the component Core. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2007-1735. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2017-6411 | D-Link DSL-2730U C1 IN_1.00 cross-site request forgery (EDB-41478 / BID-96560)
5 months 1 week ago
A vulnerability classified as problematic has been found in D-Link DSL-2730U C1 IN_1.00. Affected is an unknown function. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2017-6411. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com