3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2011-5179
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.7%
2011 0 PoCs

Cross-site scripting (XSS) vulnerability in skysa-official/skysa.php in Skysa App Bar Integration plugin, possibly before 1.04, for WordPress allows remote attackers to inject arbitrary web script or HTML via the submit parameter.

CVE-2011-4336
Wiki CMS Groupware Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.9%
2011 1 PoC

Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php.

CVE-2011-2780
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.9%
2011 3 PoCs

Directory traversal vulnerability in includes/lib/gz.php in Chyrp 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, a different vulnerability than CVE-2011-2744.

CVE-2011-5181
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.0%
2011 0 PoCs

Cross-site scripting (XSS) vulnerability in clickdesk.php in ClickDesk Live Support - Live Chat plugin 2.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cdwidgetid parameter. NOTE: some of these details are obtained from third party information.

CVE-2011-5107
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.8%
2011 0 PoCs

Cross-site scripting (XSS) vulnerability in post_alert.php in Alert Before Your Post plugin, possibly 0.1.1 and earlier, for WordPress allows remote attackers to inject arbitrary web script or HTML via the name parameter.

CVE-2011-4618
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.9%
2011 0 PoCs

Cross-site scripting (XSS) vulnerability in advancedtext.php in Advanced Text Widget plugin before 2.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter.

CVE-2011-2744
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
1.7%
2011 3 PoCs

Directory traversal vulnerability in Chyrp 2.1 and earlier allows remote attackers to include and execute arbitrary local files via a ..%2F (encoded dot dot slash) in the action parameter to the default URI.

CVE-2011-3315
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
51.1%
2011 0 PoCs

Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x before 7.1(5b)SU2, and 8.x before 8.0(3), and Cisco Unified Contact Center Express (aka Unified CCX or UCCX) and Cisco Unified IP Interactive Voice Response (Unified IP-IVR) before 6.0(1)SR1ES8, 7.0(x) before 7.0(2)ES1, 8.0(x) through 8.0(2)SU3, and 8.5(x) before 8.5(1)SU2, allows remote attackers to read arbitrary files via a crafted URL, aka Bug IDs CSCth09343 and CSCts44049.

CVE-2011-4640
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
13.6%
2011 0 PoCs

Directory traversal vulnerability in logs-x.php in SpamTitan WebTitan before 3.60 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the fname parameter in a view action.

CVE-2011-0049
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
90.6%
2011 2 PoCs

Directory traversal vulnerability in the _list_file_get function in lib/Majordomo.pm in Majordomo 2 before 20110131 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the help command, as demonstrated using (1) a crafted email and (2) cgi-bin/mj_wwwusr in the web interface.

CVE-2011-4926
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.1%
2011 0 PoCs

Cross-site scripting (XSS) vulnerability in adminimize/adminimize_page.php in the Adminimize plugin before 1.7.22 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter.

CVE-2011-5265
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
6.1%
2011 0 PoCs

Cross-site scripting (XSS) vulnerability in cached_image.php in the Featurific For WordPress plugin 1.6.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the snum parameter. NOTE: this has been disputed by a third party.

CVE-2011-5252
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
17.2%
2011 1 PoC

Open redirect vulnerability in Users/Account/LogOff in Orchard 1.0.x before 1.0.21, 1.1.x before 1.1.31, 1.2.x before 1.2.42, and 1.3.x before 1.3.10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the ReturnUrl parameter.

CVE-2011-1669
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.2%
2011 2 PoCs

Directory traversal vulnerability in wp-download.php in the WP Custom Pages module 0.5.0.1 for WordPress allows remote attackers to read arbitrary files via ..%2F (encoded dot dot) sequences in the url parameter.

CVE-2011-4804
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
10.1%
2011 0 PoCs

Directory traversal vulnerability in the obSuggest (com_obsuggest) component before 1.8 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

CVE-2011-4624
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.5%
2011 0 PoCs

Cross-site scripting (XSS) vulnerability in facebook.php in the GRAND FlAGallery plugin (flash-album-gallery) before 1.57 for WordPress allows remote attackers to inject arbitrary web script or HTML via the i parameter.

CVE-2011-5106
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.0%
2011 0 PoCs

Cross-site scripting (XSS) vulnerability in edit-post.php in the Flexible Custom Post Type plugin before 0.1.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter.

CVE-2002-1131
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.4%
2002 0 PoCs

Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as other web users via (1) addressbook.php, (2) options.php, (3) search.php, or (4) help.php.

CVE-2022-25237
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.1%
2022 1 PoC

Bonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude pattern used in the RestAPIAuthorizationFilter. By appending ;i18ntranslation or /../i18ntranslation/ to the end of a URL, users with no privileges can access privileged API endpoints. This can lead to remote code execution by abusing the privileged API actions.

CVE-2022-25488
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
59.8%
2022 0 PoCs

Atom CMS v2.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/ajax/avatar.php.