Page 3 of 19 results (0.016 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

Cross-site scripting vulnerability in BackupGuard prior to version 1.1.47 allows an attacker to inject arbitrary web script or HTML via unspecified vectors. Una vulnerabilidad de tipo Cross-Site Scripting (XSS) en BackupGuard en versiones anteriores a la 1.1.47 permite a atacantes remotos inyectar scripts web o HTML arbitrarios utilizando vectores no especificados. • https://jvn.jp/en/jp/JVN58559719/index.html https://wordpress.org/plugins/backup/#developers • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

The Backup Guard plugin before 1.1.47 for WordPress has multiple XSS issues. El complemento Backup Guard versión anterior a 1.1.47 para WordPress tiene múltiples problemas XSS. • https://wordpress.org/plugins/backup/#developers • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

Vulnerability in wordpress plugin flickr-picture-backup v0.7, The code in flickr-picture-download.php doesn't check to see if the user is authenticated or that they have permission to upload files. Existe una vulnerabilidad en el plugin flickr-picture-backup v0.7 de WordPress. El código en flickr-picture-download.php no verifica si el usuario está autenticado o tiene permisos para subir archivos. • http://www.vapidlabs.com/advisory.php?v=190 https://wordpress.org/plugins/flickr-picture-backup • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

Cross-site scripting (XSS) vulnerability in the WordPress Backup to Dropbox plugin before 4.1 for WordPress. Vulnerabilidad de tipo Cross-site scripting (XSS) en el plugin WordPress Backup to Dropbox, en versiones anteriores a la 4.1. • http://www.securityfocus.com/bid/75082 https://security.szurek.pl/wordpress-backup-to-dropbox-40-reflected-xss.html https://wordpress.org/plugins/wordpress-backup-to-dropbox • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.5EPSS: 10%CPEs: 1EXPL: 3

Directory traversal vulnerability in download.php in the DB Backup plugin 4.5 and earlier for Wordpress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. Vulnerabilidad de salto de directorio en download.php en el plugin DB Backup 4.5 y anteriores para Wordpress permite a atacantes remotos leer ficheros arbitrarios a través de un .. (punto punto) en el parámetro file. • https://www.exploit-db.com/exploits/35378 http://seclists.org/oss-sec/2014/q4/1059 https://exchange.xforce.ibmcloud.com/vulnerabilities/99368 https://wpvulndb.com/vulnerabilities/7726 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •