XML External Entity via '.AOP' files used by MX-AOPC Server result in remote file disclosure. If local user opens a specially crafted malicious MX-AOPC Server file type.
Remote attackers can DOS MXView server by sending large string of junk characters for the user ID and password field login credentials.
Jobscript4Web 4.5 is vulnerable to authentication bypass. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable application. This will allow the attacker to bypass authentication and gain access to the application.
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the WordPress Copysafe Web plugin. An attacker could exploit this vulnerability to change the plugin settings by sending a malicious POST request to the vulnerable endpoint.
A Cross-Site Request Forgery (CSRF) vulnerability in WordPress WHIZZ allows attackers to delete any WordPress users and change plugins status. An attacker can include malicious code in a page, which when visited by an authenticated user, can delete users and change plugins status.
e107 CMS version 2.1.4 is vulnerable to cross-site request forgery in plugin-installing, meta-changing and settings-changing, a malicious web page can use forged requests to make e107 download and install a plug-in provided by the attacker.
QNAP QTS web user interface CGI binaries include Command Injection (CWE-77) vulnerabilities. An unauthenticated attacker can execute arbitrary commands on the targeted device.
HTML is not escaped and there is no CSRF prevention, meaning attackers can put arbitrary HTML content onto the settings page. Visit the following page, click on the submit button, then visit the plugin’s options page: <form method="POST" action="http://localhost/wp-admin/options-general.php?page=wordpress-firewall-2%2Fwordpress-firewall-2.php"> <input type="text" name="email_address" value=""><script>alert(1)</script>"> <input type="text" name="set_email" value="Set Email"> <input type="submit"> </form> In a real attack, forms can be submitted automatically and spear-phishing attacks can be convincing.
D-Link DWR-116 with firmware before V1.05b09 suffers from vulnerability which leads to unathorized file download from device filesystem.
An attacker can exploit a SQL injection vulnerability in My Gaming Ladder System 6.0 to gain access to sensitive information such as staff IDs, display names, passwords, emails, titles, access levels, and contact information.