Classic
by WordPress
CVEs (13)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-43329 | 0.01 | — | 0.09 | Aug 25, 2022 | A SQL injection vulnerability in license_update.php in Mumara Classic through 2.93 allows a remote unauthenticated attacker to execute arbitrary SQL commands via the license parameter. | |||
| CVE-2021-43058 | 0.00 | — | 0.00 | Nov 1, 2021 | An open redirect vulnerability exists in Replicated Classic versions prior to 2.53.1 that could lead to spoofing. To exploit this vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link, redirecting the user to an… | |||
| CVE-2021-40543 | 0.00 | — | 0.00 | Oct 11, 2021 | Opensis-Classic Version 8.0 is affected by a SQL injection vulnerability due to a lack of sanitization of input data at two parameters $_GET['usrid'] and $_GET['prof_id'] in the PasswordCheck.php file. | |||
| CVE-2020-10590 | 0.00 | — | 0.00 | Jul 28, 2021 | Replicated Classic 2.x versions have an improperly secured API that exposes sensitive data from the Replicated Admin Console configuration. An attacker with network access to the Admin Console port (8800) on the Replicated Classic server could retrieve the TLS Keypair (Cert and… | |||
| CVE-2019-13261 | 0.00 | — | 0.00 | Jul 4, 2019 | XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000328384. | |||
| CVE-2019-13257 | 0.00 | — | 0.00 | Jul 4, 2019 | XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x00000000003273aa. | |||
| CVE-2019-13255 | 0.00 | — | 0.00 | Jul 4, 2019 | XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000327464. | |||
| CVE-2019-13254 | 0.00 | — | 0.00 | Jul 4, 2019 | XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000032e808. | |||
| CVE-2019-13253 | 0.00 | — | 0.00 | Jul 4, 2019 | XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000385474. | |||
| CVE-2019-13085 | 0.00 | — | 0.00 | Jun 30, 2019 | XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000030ecfa. | |||
| CVE-2019-13083 | 0.00 | — | 0.00 | Jun 30, 2019 | XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000384e2a. | |||
| CVE-2019-9967 | 0.00 | — | 0.00 | Mar 24, 2019 | XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlPrefixUnicodeString. | |||
| CVE-2007-4483 | 0.00 | — | 0.01 | Aug 22, 2007 | Cross-site scripting (XSS) vulnerability in index.php in the WordPress Classic 1.5 theme in WordPress before 2.1.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF). |
- CVE-2021-43329Aug 25, 2022risk 0.01cvss —epss 0.09
A SQL injection vulnerability in license_update.php in Mumara Classic through 2.93 allows a remote unauthenticated attacker to execute arbitrary SQL commands via the license parameter.
- CVE-2021-43058Nov 1, 2021risk 0.00cvss —epss 0.00
An open redirect vulnerability exists in Replicated Classic versions prior to 2.53.1 that could lead to spoofing. To exploit this vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link, redirecting the user to an…
- CVE-2021-40543Oct 11, 2021risk 0.00cvss —epss 0.00
Opensis-Classic Version 8.0 is affected by a SQL injection vulnerability due to a lack of sanitization of input data at two parameters $_GET['usrid'] and $_GET['prof_id'] in the PasswordCheck.php file.
- CVE-2020-10590Jul 28, 2021risk 0.00cvss —epss 0.00
Replicated Classic 2.x versions have an improperly secured API that exposes sensitive data from the Replicated Admin Console configuration. An attacker with network access to the Admin Console port (8800) on the Replicated Classic server could retrieve the TLS Keypair (Cert and…
- CVE-2019-13261Jul 4, 2019risk 0.00cvss —epss 0.00
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000328384.
- CVE-2019-13257Jul 4, 2019risk 0.00cvss —epss 0.00
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x00000000003273aa.
- CVE-2019-13255Jul 4, 2019risk 0.00cvss —epss 0.00
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000327464.
- CVE-2019-13254Jul 4, 2019risk 0.00cvss —epss 0.00
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000032e808.
- CVE-2019-13253Jul 4, 2019risk 0.00cvss —epss 0.00
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000385474.
- CVE-2019-13085Jun 30, 2019risk 0.00cvss —epss 0.00
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000030ecfa.
- CVE-2019-13083Jun 30, 2019risk 0.00cvss —epss 0.00
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000384e2a.
- CVE-2019-9967Mar 24, 2019risk 0.00cvss —epss 0.00
XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlPrefixUnicodeString.
- CVE-2007-4483Aug 22, 2007risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in index.php in the WordPress Classic 1.5 theme in WordPress before 2.1.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF).