Show filters
77 Total Results
Displaying 11-20 of 77
Sort by:
Attacker Value
Unknown

CVE-2022-45894

Disclosure Date: December 25, 2022 (last updated October 08, 2023)
GetFile.aspx in Planet eStream before 6.72.10.07 allows ..\ directory traversal to read arbitrary local files.
Attacker Value
Unknown

CVE-2022-45893

Disclosure Date: December 25, 2022 (last updated October 08, 2023)
Planet eStream before 6.72.10.07 allows a low-privileged user to gain access to administrative and high-privileged user accounts by changing the value of the ON cookie. A brute-force attack can calculate a value that provides permanent access.
Attacker Value
Unknown

CVE-2022-45892

Disclosure Date: December 25, 2022 (last updated October 08, 2023)
In Planet eStream before 6.72.10.07, multiple Stored Cross-Site Scripting (XSS) vulnerabilities exist: Disclaimer, Search Function, Comments, Batch editing tool, Content Creation, Related Media, Create new user, and Change Username.
Attacker Value
Unknown

CVE-2022-45891

Disclosure Date: December 25, 2022 (last updated October 08, 2023)
Planet eStream before 6.72.10.07 allows attackers to call restricted functions, and perform unauthenticated uploads (Upload2.ashx) or access content uploaded by other users (View.aspx after Ajax.asmx/SaveGrantAccessList).
Attacker Value
Unknown

CVE-2022-45890

Disclosure Date: December 25, 2022 (last updated October 08, 2023)
In Planet eStream before 6.72.10.07, a Reflected Cross-Site Scripting (XSS) vulnerability exists via any metadata filter field (e.g., search within Default.aspx with the r or fo parameter).
Attacker Value
Unknown

CVE-2022-45889

Disclosure Date: December 25, 2022 (last updated October 08, 2023)
Planet eStream before 6.72.10.07 allows a remote attacker (who is a publisher or admin) to obtain access to all records stored in the database, and achieve the ability to execute arbitrary SQL commands, via Search (the StatisticsResults.aspx flt parameter).
Attacker Value
Unknown

CVE-2022-30422

Disclosure Date: June 17, 2022 (last updated February 23, 2025)
Proietti Tech srl Planet Time Enterprise 4.2.0.1,4.2.0.0,4.1.0.0,4.0.0.0,3.3.1.0,3.3.0.0 is vulnerable to Remote code execution via the Viewstate parameter.
Attacker Value
Unknown

CVE-2020-9314

Disclosure Date: May 10, 2020 (last updated February 21, 2025)
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the productNameSrc parameter to an admingui URI. This issue exists because of an incomplete fix for CVE-2012-0516. NOTE: a related support policy can be found in the www.oracle.com references attached to this CVE.
Attacker Value
Unknown

CVE-2020-9315

Disclosure Date: May 10, 2020 (last updated February 21, 2025)
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/version URIs in the Administration console, as demonstrated by unauthenticated read access to encryption keys. NOTE: a related support policy can be found in the www.oracle.com references attached to this CVE.
Attacker Value
Unknown

CVE-2014-4592

Disclosure Date: December 27, 2019 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in rss.class/scripts/magpie_debug.php in the WP-Planet plugin 0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the url parameter.