2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2015-4063
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.1%
2015 2 PoCs

Cross-site scripting (XSS) vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the where1 parameter in the nsp_search page to wp-admin/admin.php.

CVE-2004-0519
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2004 0 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php.

CVE-2012-0901
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2012 0 PoCs

Cross-site scripting (XSS) vulnerability in yousaytoo.php in YouSayToo auto-publishing plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the submit parameter.

CVE-2012-4242
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.0%
2012 0 PoCs

Cross-site scripting (XSS) vulnerability in the MF Gig Calendar plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the query string to the calendar page.

CVE-2012-5321
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
23.1%
2012 2 PoCs

tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attacks via the url parameter, aka "frame injection."

CVE-2012-0996
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.0%
2012 0 PoCs

Multiple directory traversal vulnerabilities in 11in1 1.2.1 stable 12-31-2011 allow remote attackers to read arbitrary files via a .. (dot dot) in the class parameter to (1) index.php or (2) admin/index.php.

CVE-2012-0394
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.6%
2012 2 PoCs

The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands via unspecified vectors. NOTE: the vendor characterizes this behavior as not "a security vulnerability itself.

CVE-2012-1226
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.6%
2012 4 PoCs

Multiple directory traversal vulnerabilities in Dolibarr CMS 3.2.0 Alpha allow remote attackers to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in the (1) file parameter to document.php or (2) backtopage parameter in a create action to comm/action/fiche.php.

CVE-2012-0991
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
22.9%
2012 0 PoCs

Multiple directory traversal vulnerabilities in OpenEMR 4.1.0 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the formname parameter to (1) contrib/acog/print_form.php; or (2) load_form.php, (3) view_form.php, or (4) trend_form.php in interface/patient_file/encounter.

CVE-2012-6499
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
46.4%
2012 0 PoCs

Open redirect vulnerability in age-verification.php in the Age Verification plugin 0.4 and earlier for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_to parameter.

CVE-2012-2371
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.7%
2012 1 PoC

Cross-site scripting (XSS) vulnerability in index.php in the WP-FaceThumb plugin 0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the pagination_wp_facethumb parameter.

CVE-2012-0896
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.8%
2012 2 PoCs

Absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to read arbitrary files via the f parameter.

CVE-2012-5913
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.5%
2012 2 PoCs

Cross-site scripting (XSS) vulnerability in wp-integrator.php in the WordPress Integrator module 1.32 for WordPress allows remote attackers to inject arbitrary web script or HTML via the redirect_to parameter to wp-login.php.

CVE-2012-4878
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.8%
2012 2 PoCs

Absolute path traversal vulnerability in controlcenter.php in FlatnuX CMS 2011 08.09.2 allows remote administrators to read arbitrary files via a full pathname in the dir parameter in a contents/Files action.

CVE-2012-0981
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.8%
2012 0 PoCs

Directory traversal vulnerability in phpShowtime 2.0 allows remote attackers to list arbitrary directories and image files via a .. (dot dot) in the r parameter to index.php. NOTE: Some of these details are obtained from third party information.

CVE-2012-4253
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
30.2%
2012 1 PoC

Multiple directory traversal vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) language parameter to learn/cubemail/install.php or (2) f parameter learn/cubemail/filemanagement.php, or execute arbitrary local files via a .. (dot dot) in the (3) config parameter to learn/cubemail/menu.php.

CVE-2014-9606
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
9.4%
2014 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) server parameter to remotereporter/load_logfiles.php, (2) customctid parameter to webadmin/policy/category_table_ajax.php, (3) urllist parameter to webadmin/alert/alert.php, (4) QUERY_STRING to webadmin/ajaxfilemanager/ajax_get_file_listing.php, or (5) PATH_INFO to webadmin/policy/policy_table_ajax.php/.

CVE-2015-3224
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
85.3%
2015 5 PoCs

request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address, which allows remote attackers to bypass the whitelisted_ips protection mechanism via a crafted request.

CVE-2012-1835
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.0%
2012 0 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in the All-in-One Event Calendar plugin 1.4 and 1.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to app/view/agenda-widget-form.php; (2) args, (3) title, (4) before_title, or (5) after_title parameter to app/view/agenda-widget.php; (6) button_value parameter to app/view/box_publish_button.php; or (7) msg parameter to /app/view/save_successful.php.

CVE-2012-0392
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
75.0%
2012 1 PoC

The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafted HTTP Cookie header that triggers Java code execution through a static method.