Show filters
25 Total Results
Displaying 11-20 of 25
Sort by:
Attacker Value
Unknown
CVE-2019-17392
Disclosure Date: November 26, 2019 (last updated November 27, 2024)
Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.
0
Attacker Value
Unknown
CVE-2017-18639
Disclosure Date: November 06, 2019 (last updated November 27, 2024)
Progress Sitefinity CMS before 10.1 allows XSS via /Pages Parameter : Page Title, /Content/News Parameter : News Title, /Content/List Parameter : List Title, /Content/Documents/LibraryDocuments/incident-request-attachments Parameter : Document Title, /Content/Images/LibraryImages/newsimages Parameter : Image Title, /Content/links Parameter : Link Title, /Content/links Parameter : Link Title, or /Content/Videos/LibraryVideos/default-video-library Parameter : Video Title.
0
Attacker Value
Unknown
CVE-2019-7215
Disclosure Date: June 06, 2019 (last updated November 08, 2023)
Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie in the browser, but it remains valid on the server side. This means the cookie can be reused to maintain access to the account, even if the account credentials and permissions are changed.
0
Attacker Value
Unknown
CVE-2018-17054
Disclosure Date: October 03, 2018 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to login request parameters, a different vulnerability than CVE-2018-17053.
0
Attacker Value
Unknown
CVE-2018-17053
Disclosure Date: October 03, 2018 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to login request parameters, a different vulnerability than CVE-2018-17054.
0
Attacker Value
Unknown
CVE-2018-17056
Disclosure Date: September 28, 2018 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in ServiceStack in Progress Sitefinity CMS versions 10.2 through 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2018-17055
Disclosure Date: September 28, 2018 (last updated November 27, 2024)
An arbitrary file upload vulnerability in Progress Sitefinity CMS versions 4.0 through 11.0 related to image uploads.
0
Attacker Value
Unknown
CVE-2017-18178
Disclosure Date: February 12, 2018 (last updated November 26, 2024)
Authenticate/SWT in Progress Sitefinity 9.1 has an open redirect issue in which an authentication token is sent to the redirection target, if the target is specified using a certain %40 syntax. This is fixed in 10.1.
0
Attacker Value
Unknown
CVE-2017-18175
Disclosure Date: February 12, 2018 (last updated November 26, 2024)
Progress Sitefinity 9.1 has XSS via the Content Management Template Configuration (aka Templateconfiguration), as demonstrated by the src attribute of an IMG element. This is fixed in 10.1.
0
Attacker Value
Unknown
CVE-2017-18176
Disclosure Date: February 12, 2018 (last updated November 26, 2024)
Progress Sitefinity 9.1 has XSS via file upload, because JavaScript code in an HTML file has the same origin as the application's own code. This is fixed in 10.1.
0