Security Vulnerabilities
- CVEs Published In January 2020
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter.
Local file inclusion in WebCalendar before 1.2.5.
Pinboard 1.0.6 theme for Wordpress has XSS.
IrfanView FlashPix Plugin 4.3.4 0 has an Integer Overflow Vulnerability
XnView 2.03 has a stack-based buffer overflow vulnerability
XnView 2.03 has an integer overflow vulnerability
WordPress Portable phpMyAdmin Plugin has an authentication bypass vulnerability
Wiz 5.0.3 has a user mode write access violation
OSSIM before 4.3.3.1 has tele_compress.php path traversal vulnerability
Proxmox VE prior to 3.2: 'AccessControl.pm' User Enumeration Vulnerability