Show filters
66 Total Results
Displaying 11-20 of 66
Sort by:
Attacker Value
Unknown
CVE-2019-9105
Disclosure Date: May 31, 2019 (last updated November 27, 2024)
The WebApp v04.68 in the supervisor on SAET Impianti Speciali TEBE Small 05.01 build 1137 devices allows remote attackers to make several types of API calls without authentication, as demonstrated by retrieving password hashes via an inc/utils/REST_API.php?command=CallAPI&customurl=alladminusers call.
0
Attacker Value
Unknown
CVE-2017-1002002
Disclosure Date: September 14, 2017 (last updated November 26, 2024)
Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/
0
Attacker Value
Unknown
CVE-2017-11666
Disclosure Date: July 26, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in js/ViewerPanel.js in the file previewer plugin in Kopano WebApp versions 3.3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a specially crafted previewable file.
0
Attacker Value
Unknown
CVE-2014-9465
Disclosure Date: February 19, 2015 (last updated October 05, 2023)
senddocument.php in Zarafa WebApp before 2.0 beta 3 and WebAccess in Zarafa Collaboration Platform (ZCP) 7.x before 7.1.12 beta 1 and 7.2.x before 7.2.0 beta 1 allows remote attackers to cause a denial of service (/tmp disk consumption) by uploading a large number of files.
0
Attacker Value
Unknown
CVE-2014-5449
Disclosure Date: October 20, 2014 (last updated October 05, 2023)
Zarafa WebAccess 4.1 and WebApp uses world-readable permissions for the files in their tmp directory, which allows local users to obtain sensitive information by reading temporary session data.
0
Attacker Value
Unknown
CVE-2014-5447
Disclosure Date: October 20, 2014 (last updated October 05, 2023)
Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0103.
0
Attacker Value
Unknown
CVE-2014-0103
Disclosure Date: July 29, 2014 (last updated October 05, 2023)
WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive information by reading the PHP session files.
0
Attacker Value
Unknown
CVE-2012-4551
Disclosure Date: November 30, 2012 (last updated October 05, 2023)
Use-after-free vulnerability in libunity-webapps before 2.4.1 allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via a crafted web site, related to "certain hash tables."
0
Attacker Value
Unknown
CVE-2010-1438
Disclosure Date: May 06, 2010 (last updated October 04, 2023)
Web Application Finger Printer (WAFP) 0.01-26c3 uses fixed pathnames under /tmp for temporary files and directories, which (1) allows local users to cause a denial of service (application outage) by creating a file with a pathname that the product expects is available for its own internal use, (2) allows local users to overwrite arbitrary files via symlink attacks on certain files in /tmp, (3) might allow local users to delete arbitrary files and directories via a symlink attack on a directory under /tmp, and (4) might make it easier for local users to obtain sensitive information by reading files in a directory under /tmp, related to (a) lib/wafp_pidify.rb, (b) utils/generate_wafp_fingerprint.sh, (c) utils/online_update.sh, and (d) utils/extract_from_db.sh.
0
Attacker Value
Unknown
CVE-2007-3422
Disclosure Date: June 26, 2007 (last updated October 04, 2023)
The getcgi function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 attempts to parse query strings that contain (1) non-printing characters, (2) certain printing characters that do not commonly occur in URLs, or (3) invalid URL encoding sequences, which has unknown impact and remote attack vectors.
0