Show filters
66 Total Results
Displaying 11-20 of 66
Sort by:
Attacker Value
Unknown

CVE-2019-9105

Disclosure Date: May 31, 2019 (last updated November 27, 2024)
The WebApp v04.68 in the supervisor on SAET Impianti Speciali TEBE Small 05.01 build 1137 devices allows remote attackers to make several types of API calls without authentication, as demonstrated by retrieving password hashes via an inc/utils/REST_API.php?command=CallAPI&customurl=alladminusers call.
0
Attacker Value
Unknown

CVE-2017-1002002

Disclosure Date: September 14, 2017 (last updated November 26, 2024)
Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/
0
Attacker Value
Unknown

CVE-2017-11666

Disclosure Date: July 26, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in js/ViewerPanel.js in the file previewer plugin in Kopano WebApp versions 3.3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a specially crafted previewable file.
0
Attacker Value
Unknown

CVE-2014-9465

Disclosure Date: February 19, 2015 (last updated October 05, 2023)
senddocument.php in Zarafa WebApp before 2.0 beta 3 and WebAccess in Zarafa Collaboration Platform (ZCP) 7.x before 7.1.12 beta 1 and 7.2.x before 7.2.0 beta 1 allows remote attackers to cause a denial of service (/tmp disk consumption) by uploading a large number of files.
0
Attacker Value
Unknown

CVE-2014-5449

Disclosure Date: October 20, 2014 (last updated October 05, 2023)
Zarafa WebAccess 4.1 and WebApp uses world-readable permissions for the files in their tmp directory, which allows local users to obtain sensitive information by reading temporary session data.
0
Attacker Value
Unknown

CVE-2014-5447

Disclosure Date: October 20, 2014 (last updated October 05, 2023)
Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0103.
0
Attacker Value
Unknown

CVE-2014-0103

Disclosure Date: July 29, 2014 (last updated October 05, 2023)
WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive information by reading the PHP session files.
0
Attacker Value
Unknown

CVE-2012-4551

Disclosure Date: November 30, 2012 (last updated October 05, 2023)
Use-after-free vulnerability in libunity-webapps before 2.4.1 allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via a crafted web site, related to "certain hash tables."
0
Attacker Value
Unknown

CVE-2010-1438

Disclosure Date: May 06, 2010 (last updated October 04, 2023)
Web Application Finger Printer (WAFP) 0.01-26c3 uses fixed pathnames under /tmp for temporary files and directories, which (1) allows local users to cause a denial of service (application outage) by creating a file with a pathname that the product expects is available for its own internal use, (2) allows local users to overwrite arbitrary files via symlink attacks on certain files in /tmp, (3) might allow local users to delete arbitrary files and directories via a symlink attack on a directory under /tmp, and (4) might make it easier for local users to obtain sensitive information by reading files in a directory under /tmp, related to (a) lib/wafp_pidify.rb, (b) utils/generate_wafp_fingerprint.sh, (c) utils/online_update.sh, and (d) utils/extract_from_db.sh.
0
Attacker Value
Unknown

CVE-2007-3422

Disclosure Date: June 26, 2007 (last updated October 04, 2023)
The getcgi function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 attempts to parse query strings that contain (1) non-printing characters, (2) certain printing characters that do not commonly occur in URLs, or (3) invalid URL encoding sequences, which has unknown impact and remote attack vectors.
0