Show filters
31 Total Results
Displaying 11-20 of 31
Sort by:
Attacker Value
Unknown
CVE-2019-12773
Disclosure Date: July 14, 2020 (last updated February 21, 2025)
An issue was discovered in Verint Impact 360 15.1. At wfo/help/help_popup.jsp, the helpURL parameter can be changed to embed arbitrary content inside of an iFrame. Attackers may use this in conjunction with social engineering to embed malicious scripts or phishing pages on a site where this product is installed, given the attacker can convince a victim to visit a crafted link.
0
Attacker Value
Unknown
CVE-2020-4236
Disclosure Date: March 30, 2020 (last updated November 27, 2024)
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 could allow an authenticated user to cause a denial of service due to improper content parsing in the project management module. IBM X-Force ID: 175409.
0
Attacker Value
Unknown
CVE-2020-4237
Disclosure Date: March 30, 2020 (last updated February 21, 2025)
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 175410.
0
Attacker Value
Unknown
CVE-2020-4239
Disclosure Date: March 30, 2020 (last updated February 21, 2025)
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 175412.
0
Attacker Value
Unknown
CVE-2020-4235
Disclosure Date: March 30, 2020 (last updated February 21, 2025)
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 175408.
0
Attacker Value
Unknown
CVE-2020-4238
Disclosure Date: March 30, 2020 (last updated February 21, 2025)
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 175411.
0
Attacker Value
Unknown
CVE-2019-4681
Disclosure Date: March 23, 2020 (last updated February 21, 2025)
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 171734.
0
Attacker Value
Unknown
CVE-2020-10257
Disclosure Date: March 10, 2020 (last updated February 21, 2025)
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
0
Attacker Value
Unknown
CVE-2019-17405
Disclosure Date: November 25, 2019 (last updated November 27, 2024)
Nokia IMPACT < 18A: has Reflected self XSS
0
Attacker Value
Unknown
CVE-2019-17403
Disclosure Date: November 25, 2019 (last updated November 27, 2024)
Nokia IMPACT < 18A: An unrestricted File Upload vulnerability was found that may lead to Remote Code Execution.
0