Show filters
109 Total Results
Displaying 11-20 of 109
Sort by:
Attacker Value
Unknown
CVE-2017-6195
Disclosure Date: May 18, 2017 (last updated November 26, 2024)
Ipswitch MOVEit Transfer (formerly DMZ) allows pre-authentication blind SQL injection. The fixed versions are MOVEit Transfer 2017 9.0.0.201, MOVEit DMZ 8.3.0.30, and MOVEit DMZ 8.2.0.20.
0
Attacker Value
Unknown
CVE-2015-7676
Disclosure Date: April 15, 2016 (last updated November 25, 2024)
Ipswitch MOVEit File Transfer (formerly DMZ) 8.1 and earlier, when configured to support file view on download, allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading HTML files.
0
Attacker Value
Unknown
CVE-2015-7678
Disclosure Date: February 10, 2016 (last updated November 25, 2024)
Multiple cross-site request forgery (CSRF) vulnerabilities in Ipswitch MOVEit Mobile 1.2.0.962 and earlier allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.
0
Attacker Value
Unknown
CVE-2015-7679
Disclosure Date: February 10, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in Ipswitch MOVEit Mobile before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the query string to mobile/.
0
Attacker Value
Unknown
CVE-2015-7677
Disclosure Date: February 10, 2016 (last updated November 25, 2024)
The MOVEitISAPI service in Ipswitch MOVEit DMZ before 8.2 provides different error messages depending on whether a FileID exists, which allows remote authenticated users to enumerate FileIDs via the X-siLock-FileID parameter in a download action to MOVEitISAPI/MOVEitISAPI.dll.
0
Attacker Value
Unknown
CVE-2015-7675
Disclosure Date: February 10, 2016 (last updated November 25, 2024)
The "Send as attachment" feature in Ipswitch MOVEit DMZ before 8.2 and MOVEit Mobile before 1.2.2 allow remote authenticated users to bypass authorization and read uploaded files via a valid FileID in the (1) serverFileIds parameter to mobile/sendMsg or (2) arg01 parameter to human.aspx.
0
Attacker Value
Unknown
CVE-2015-7680
Disclosure Date: February 10, 2016 (last updated November 25, 2024)
Ipswitch MOVEit DMZ before 8.2 provides different error messages for authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of SOAP requests to machine.aspx.
0
Attacker Value
Unknown
CVE-2011-4722
Disclosure Date: December 28, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in the TFTP Server 1.0.0.24 in Ipswitch WhatsUp Gold allows remote attackers to read arbitrary files via a .. (dot dot) in the Filename field of an RRQ operation.
0
Attacker Value
Unknown
CVE-2014-3878
Disclosure Date: June 05, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the web client interface in Ipswitch IMail Server 12.3 and 12.4, possibly before 12.4.1.15, allow remote attackers to inject arbitrary web script or HTML via (1) the Name field in an add new contact action in the Contacts section or unspecified vectors in (2) an Add Group task in the Contacts section, (3) an add new event action in the Calendar section, or (4) the Task section.
0
Attacker Value
Unknown
CVE-2011-1430
Disclosure Date: March 16, 2011 (last updated October 04, 2023)
The STARTTLS implementation in the server in Ipswitch IMail 11.03 and earlier does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.
0