2 results (0.025 seconds)

CVSS: 7.8EPSS: 0%CPEs: 6EXPL: 0

24 Feb 2020 — The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects Endpoint Protection, Cloud Optix, Mobile, Intercept X Endpoint, Intercept X for Server, and Secure Web Gateway. NOTE: the vendor feels that this does not apply to endpoint-protection products because the virus would be detected upon extraction. El motor de análisis Sophos AV versiones anteriores a 14-01-2020 permite una omisión de la detección de virus por medio de un archivo ZIP diseñado. Es... • https://blog.zoller.lu/p/release-mode-coordinated-disclosure-ref.html • CWE-436: Interpretation Conflict •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

20 Apr 2015 — iThemes Mobile before 1.2.8 for WordPress has XSS via add_query_arg() and remove_query_arg(). iThemes Mobile antes de 1.2.8 para WordPress tiene una vulnerabilidad XSS a través de add_query_arg () y remove_query_arg (). • https://blog.sucuri.net/2015/04/security-advisory-xss-vulnerability-affecting-multiple-wordpress-plugins.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •