Page 13 of 126 results (0.005 seconds)

CVSS: 6.4EPSS: 0%CPEs: 1EXPL: 0

28 Oct 2022 — Stored Cross-Site Scripting (XSS) vulnerability in John West Slideshow SE plugin <= 2.5.5 versions. The Slideshow SE plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Stored Cross-Site Scripting (XSS) ... • https://patchstack.com/database/vulnerability/slideshow-se/wordpress-slideshow-se-plugin-2-5-5-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.8EPSS: 0%CPEs: 3EXPL: 0

16 Jun 2020 — A CWE-88: Argument Injection or Modification vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could cause unauthorized write access when opening the project file. Una CWE-88: Se presenta una vulnerabilidad de Inyección de Argumentos o Modificación en EcoStruxure Operator Terminal Expert versiones 3.1, Service Pack 1 y anteriores (anteriormente conocido como Vijeo XD) que podría causar un acceso de escritura no autorizado cuando se ab... • https://www.se.com/ww/en/download/document/SEVD-2020-133-04 • CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') •

CVSS: 9.0EPSS: 0%CPEs: 1EXPL: 0

29 Jul 2019 — SmokeDetector intentionally does automatic deployments of updated copies of SmokeDetector without server operator authority. SmokeDetector lleva a cabo intencionalmente implementaciones automáticas de copias actualizadas de SmokeDetector sin la autoridad del operador del servidor. • https://github.com/Charcoal-SE/SmokeDetector/security/advisories/GHSA-5w85-7mwr-v44q • CWE-669: Incorrect Resource Transfer Between Spheres •

CVSS: 9.8EPSS: 12%CPEs: 1EXPL: 4

06 Jun 2015 — Directory traversal vulnerability in download_audio.php in the SE HTML5 Album Audio Player (se-html5-album-audio-player) plugin 1.1.0 and earlier for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. Vulnerabilidad de salto de directorio en download_audio.php en el plugin SE HTML5 Album Audio Player (se-html5-album-audio-player) 1.1.0 y anteriores para WordPress permite a atacantes remotos leer ficheros arbitrarios a través de un .. (punto punto) en el parám... • https://packetstorm.news/files/id/132266 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 2

09 Jan 2009 — SQL injection vulnerability in index.php in EZpack 4.2b2 allows remote attackers to execute arbitrary SQL commands via the qType parameter in a webboard prog action. Vulnerabilidad de inyección SQL en index.php en EZpack v4.2b2 permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro "qType" en una acción "webboard prog". • https://www.exploit-db.com/exploits/7680 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 2

09 Jan 2009 — Cross-site scripting (XSS) vulnerability in index.php in EZpack 4.2b2 allows remote attackers to inject arbitrary web script or HTML via the mdfd parameter in a prog action. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en index.php en EZpack v4.2b2 permite a atacantes remotos inyectar web script o HTML a través del parámetro "mdfd" en una acción "prog". • https://www.exploit-db.com/exploits/7680 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •