Lucene search

K

Clone Security Vulnerabilities

cve
cve

CVE-2024-5942

The Page and Post Clone plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0 via the 'content_clone' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access....

4.3CVSS

4.4AI Score

0.001EPSS

2024-06-29 05:15 AM
12
cve
cve

CVE-2023-38395

Missing Authorization vulnerability in Afzal Multani WP Clone Menu.This issue affects WP Clone Menu: from n/a through...

5.4CVSS

5.6AI Score

0.0004EPSS

2024-06-12 10:15 AM
22
cve
cve

CVE-2024-33636

Missing Authorization vulnerability in Mahesh Vora WP Page Post Widget Clone.This issue affects WP Page Post Widget Clone: from n/a through...

5.4CVSS

6.8AI Score

0.0004EPSS

2024-04-29 09:15 AM
25
cve
cve

CVE-2024-2294

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.7 via the backup_name parameter in the backuply_download_backup function. This makes it possible for attackers to have an account with only...

4.9CVSS

9.2AI Score

0.0004EPSS

2024-03-16 02:15 AM
35
cve
cve

CVE-2024-0842

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 1.2.5. This is due to direct access of the backuply/restore_ins.php file and. This makes it possible for unauthenticated attackers to make excessive...

7.5CVSS

7.5AI Score

0.0005EPSS

2024-02-09 05:15 AM
11
cve
cve

CVE-2024-0697

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.3 via the node_id parameter in the backuply_get_jstree function. This makes it possible for attackers with administrator privileges or higher to...

6.5CVSS

5.2AI Score

0.001EPSS

2024-01-27 05:15 AM
11
cve
cve

CVE-2023-6750

The Clone WordPress plugin before 2.4.3 uses buffer files to store in-progress backup informations, which is stored at a publicly accessible, statically defined file...

7.5CVSS

7.6AI Score

0.001EPSS

2024-01-08 07:15 PM
20
cve
cve

CVE-2023-3977

Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for...

4.3CVSS

4.7AI Score

0.001EPSS

2023-07-28 05:15 AM
14
cve
cve

CVE-2023-0958

Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with...

6.5CVSS

6.4AI Score

EPSS

2023-07-28 05:15 AM
17
cve
cve

CVE-2009-2423

SQL injection vulnerability in category.php in Ebay Clone 2009 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter in a list...

8.6AI Score

0.001EPSS

2022-10-03 04:24 PM
19
cve
cve

CVE-2009-2424

Cross-site scripting (XSS) vulnerability in search.php in Ebay Clone 2009 allows remote attackers to inject arbitrary web script or HTML via the mode...

5.9AI Score

0.001EPSS

2022-10-03 04:24 PM
25
cve
cve

CVE-2009-4858

Cross-site scripting (XSS) vulnerability in questiondetail.php in Yahoo Answers Clone allows remote attackers to inject arbitrary web script or HTML via the questionid...

5.9AI Score

0.001EPSS

2022-10-03 04:24 PM
22
cve
cve

CVE-2009-3504

SQL injection vulnerability in offers_buy.php in Alibaba Clone 3.0 allows remote attackers to execute arbitrary SQL commands via the id...

8.4AI Score

0.002EPSS

2022-10-03 04:23 PM
19
cve
cve

CVE-2018-9328

PHP Scripts Mall Redbus Clone Script 3.0.6 has XSS via the ter_from or tag parameter to...

6.1CVSS

6AI Score

0.001EPSS

2022-10-03 04:21 PM
23
cve
cve

CVE-2018-6878

Cross Site Scripting (XSS) exists in the review section in PHP Scripts Mall Hot Scripts Clone Script Classified 3.1 via the title or description...

5.4CVSS

5AI Score

0.0005EPSS

2022-10-03 04:21 PM
20
cve
cve

CVE-2010-4997

SQL injection vulnerability in index.php in OlyKit Swoopo Clone 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter in a product...

8.7AI Score

0.001EPSS

2022-10-03 04:21 PM
24
cve
cve

CVE-2010-4849

SQL injection vulnerability in countrydetails.php in Alibaba Clone B2B 3.4 allows remote attackers to execute arbitrary SQL commands via the es_id...

8.7AI Score

0.001EPSS

2022-10-03 04:21 PM
16
cve
cve

CVE-2019-6248

PHP Scripts Mall Citysearch / Hotfrog / Gelbeseiten Clone Script 2.0.1 has Reflected XSS via the srch parameter, as demonstrated by...

6.1CVSS

6AI Score

0.001EPSS

2022-10-03 04:19 PM
14
cve
cve

CVE-2015-4658

Multiple SQL injection vulnerabilities in admin/login.php in Milw0rm Clone Script 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) usr or (2) pwd...

8.8AI Score

0.001EPSS

2022-10-03 04:16 PM
23
cve
cve

CVE-2022-25900

All versions of package git-clone are vulnerable to Command Injection due to insecure usage of the --upload-pack feature of...

9.8CVSS

9.7AI Score

0.004EPSS

2022-07-01 08:15 PM
48
7
cve
cve

CVE-2022-24437

The package git-pull-or-clone before 2.0.2 are vulnerable to Command Injection due to the use of the --upload-pack feature of git which is also supported for git clone. The source includes the use of the secure child process API spawn(). However, the outpath parameter passed to it may be a...

9.8CVSS

9.9AI Score

0.002EPSS

2022-05-01 04:15 PM
664
2
cve
cve

CVE-2021-24733

The WP Post Page Clone WordPress plugin before 1.2 allows users with a role as low as Contributor to clone and view other users' draft and password-protected posts which they cannot view...

4.3CVSS

4.5AI Score

0.001EPSS

2022-01-24 08:15 AM
30
cve
cve

CVE-2019-13227

In GUI mode, deepin-clone before 1.1.3 creates a log file at the fixed path /tmp/.deepin-clone.log as root, and follows symlinks there. An unprivileged user can prepare a symlink attack there to create or overwrite files in arbitrary file system locations. The content is not attacker...

5.5CVSS

5.9AI Score

0.001EPSS

2019-07-04 12:15 PM
31
cve
cve

CVE-2019-13228

deepin-clone before 1.1.3 uses a fixed path /tmp/repo.iso in the BootDoctor::fix() function to download an ISO file, and follows symlinks there. An unprivileged user can prepare a symlink attack there to create or overwrite files in arbitrary file system locations. The content is not attacker...

4.7CVSS

5.6AI Score

0.001EPSS

2019-07-04 12:15 PM
28
cve
cve

CVE-2019-13226

deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/mount/ in the Helper::temporaryMountDevice() function to temporarily mount a file system as root. An unprivileged user can prepare a symlink at this location to have the file system mounted in an arbitrary location. By winning a.....

7CVSS

6.6AI Score

0.001EPSS

2019-07-04 12:15 PM
27
cve
cve

CVE-2019-13229

deepin-clone before 1.1.3 uses a fixed path /tmp/partclone.log in the Helper::getPartitionSizeInfo() function to write a log file as root, and follows symlinks there. An unprivileged user can prepare a symlink attack there to create or overwrite files in arbitrary file system locations. The...

5.5CVSS

5.9AI Score

0.001EPSS

2019-07-04 12:15 PM
28
cve
cve

CVE-2018-17841

SQL injection exists in Scriptzee Flippa Marketplace Clone 1.0 via the site-search sortBy or sortDir...

9.8CVSS

9.8AI Score

0.003EPSS

2019-06-19 05:15 PM
58
cve
cve

CVE-2018-16326

PHP Scripts Mall Olx Clone 3.4.2 has...

6.1CVSS

6.4AI Score

0.001EPSS

2018-10-04 09:29 PM
20
cve
cve

CVE-2018-15185

PHP Scripts Mall Naukri / Shine / Jobsite Clone Script 3.0.4 allows remote attackers to cause a denial of service (page update outage) via crafted PHP and JavaScript code in the "Current Position"...

6.5CVSS

6.6AI Score

0.001EPSS

2018-08-10 03:29 PM
26
cve
cve

CVE-2018-15184

PHP Scripts Mall Naukri / Shine / Jobsite Clone Script 3.0.4 has Stored XSS via the USERNAME field, a related issue to...

5.4CVSS

5.2AI Score

0.001EPSS

2018-08-09 07:29 PM
22
cve
cve

CVE-2018-15183

PHP Scripts Mall Myperfectresume / JobHero / Resume Clone Script 2.0.6 has Stored XSS via the Full Name and Title...

6.1CVSS

5.9AI Score

0.001EPSS

2018-08-09 07:29 PM
19
cve
cve

CVE-2018-13849

edit_requests.php in yTakkar Instagram-clone through 2018-04-23 has XSS via an onmouseover payload because of an inadequate XSS protection mechanism based on...

6.1CVSS

5.9AI Score

0.001EPSS

2018-07-10 06:29 PM
42
cve
cve

CVE-2018-11514

PHP Scripts Mall Naukri Clone Script through 3.0.3 allows Unrestricted Upload of a File with a Dangerous Type in edit_resume_det.php, as demonstrated by changing .docx to...

8.8CVSS

8.6AI Score

0.001EPSS

2018-05-28 02:29 PM
18
cve
cve

CVE-2018-6903

PHP Scripts Mall Hot Scripts Clone Script Classified v3.1 uses the client side to enforce validation of an e-mail address, which allows remote attackers to modify a registered e-mail address by removing the validation...

8.8CVSS

8.6AI Score

0.003EPSS

2018-04-12 10:29 PM
16
cve
cve

CVE-2018-9857

PHP Scripts Mall Match Clone Script 1.0.4 has XSS via the search field to searchbyid.php (aka the "View Search By Id"...

6.1CVSS

5.9AI Score

0.001EPSS

2018-04-09 07:29 AM
29
cve
cve

CVE-2018-7650

PHP Scripts Mall Hot Scripts Clone:Script Classified Version 3.1 Application is vulnerable to stored XSS within the "Add New" function for a Management User. Within the "Add New" section, the application does not sanitize user supplied input to the name parameter, and renders injected JavaScript...

4.8CVSS

5.1AI Score

0.001EPSS

2018-03-06 03:29 PM
20
cve
cve

CVE-2018-6867

Cross Site Scripting (XSS) exists in PHP Scripts Mall Alibaba Clone Script 1.0.2 via a profile...

5.4CVSS

5.2AI Score

0.0005EPSS

2018-02-23 01:29 PM
22
cve
cve

CVE-2018-6868

Cross Site Scripting (XSS) exists in PHP Scripts Mall Slickdeals / DealNews / Groupon Clone Script 3.0.2 via a User Profile Field...

5.4CVSS

5.2AI Score

0.0005EPSS

2018-02-23 01:29 PM
25
cve
cve

CVE-2018-6845

PHP Scripts Mall Multi Language Olx Clone Script 2.0.6 has XSS via the Leave Comment...

6.1CVSS

6AI Score

0.001EPSS

2018-02-12 03:29 AM
21
cve
cve

CVE-2018-6858

Cross Site Scripting (XSS) exists in PHP Scripts Mall Facebook Clone...

5.4CVSS

5.3AI Score

0.0005EPSS

2018-02-12 03:29 AM
18
cve
cve

CVE-2018-6795

PHP Scripts Mall Naukri Clone Script 3.0.3 has Stored XSS via every profile input...

5.4CVSS

5.2AI Score

0.0005EPSS

2018-02-07 09:29 PM
17
cve
cve

CVE-2018-6363

SQL Injection exists in Task Rabbit Clone 1.0 via the single_blog.php id...

9.8CVSS

9.8AI Score

0.002EPSS

2018-01-29 05:29 AM
23
cve
cve

CVE-2018-6367

SQL Injection exists in Vastal I-Tech Buddy Zone Facebook Clone 2.9.9 via the /chat_im/chat_window.php request_id parameter or the /search_events.php category...

9.8CVSS

9.8AI Score

0.002EPSS

2018-01-29 05:29 AM
29
cve
cve

CVE-2017-17904

FS Lynda Clone has XSS via the keywords parameter to tutorial/ or the edit_profile_first_name parameter to...

5.4CVSS

5.2AI Score

0.001EPSS

2017-12-27 05:08 PM
25
cve
cve

CVE-2017-17931

PHP Scripts Mall Resume Clone Script has SQL Injection via the forget.php username...

9.8CVSS

9.9AI Score

0.002EPSS

2017-12-27 05:08 PM
19
cve
cve

CVE-2017-17903

FS Lynda Clone has CSRF via user/edit_profile, as demonstrated by adding content to the user...

8.8CVSS

8.6AI Score

0.001EPSS

2017-12-27 05:08 PM
28
cve
cve

CVE-2017-17643

FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to...

9.8CVSS

9.8AI Score

0.002EPSS

2017-12-18 09:29 AM
33
cve
cve

CVE-2017-17641

Resume Clone Script 2.0.5 has SQL Injection via the preview.php id...

9.8CVSS

9.8AI Score

0.002EPSS

2017-12-13 09:29 AM
24
cve
cve

CVE-2017-17638

Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id...

9.8CVSS

9.9AI Score

0.002EPSS

2017-12-13 09:29 AM
21
cve
cve

CVE-2017-17621

Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail...

9.8CVSS

9.8AI Score

0.003EPSS

2017-12-13 09:29 AM
30
Total number of security vulnerabilities103