Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown

CVE-2020-7841

Disclosure Date: November 17, 2020 (last updated February 22, 2025)
Improper input validation vulnerability exists in TOBESOFT XPLATFORM which could cause arbitrary .hta file execution when the command string is begun with http://, https://, mailto://
Attacker Value
Unknown

CVE-2020-7825

Disclosure Date: July 15, 2020 (last updated February 21, 2025)
A vulnerability exists that could allow the execution of operating system commands on systems running MiPlatform 2019.05.16 and earlier. An attacker could execute arbitrary remote command by sending parameters to WinExec function in ExtCommandApi.dll module of MiPlatform.
Attacker Value
Unknown

CVE-2020-7815

Disclosure Date: July 03, 2020 (last updated November 28, 2024)
XPLATFORM v9.2.260 and eariler versions contain a vulnerability that could allow remote files to be downloaded by setting the arguments to the vulnerable method. this can be leveraged for code execution. File download vulnerability in ____COMPONENT____ of TOBESOFT XPLATFORM allows ____ATTACKER/ATTACK____ to cause ____IMPACT____. This issue affects: TOBESOFT XPLATFORM 9.2.250 versions prior to 9.2.260 on Windows.
Attacker Value
Unknown

CVE-2020-7806

Disclosure Date: May 06, 2020 (last updated February 21, 2025)
Tobesoft Xplatform 9.2.2.250 and earlier version have an arbitrary code execution vulnerability by using method supported by Xplatform ActiveX Control. It allows attacker to cause remote code execution.
Attacker Value
Unknown

CVE-2019-19166

Disclosure Date: May 06, 2020 (last updated February 21, 2025)
Tobesoft XPlatform v9.1, 9.2.0, 9.2.1 and 9.2.2 have a vulnerability that can load unauthorized DLL files. It allows attacker to cause remote code execution.
Attacker Value
Unknown

CVE-2019-19167

Disclosure Date: May 06, 2020 (last updated February 21, 2025)
Tobesoft Nexacro v2019.9.25.1 and earlier version have an arbitrary code execution vulnerability by using method supported by Nexacro14 ActiveX Control. It allows attacker to cause remote code execution.
Attacker Value
Unknown

CVE-2019-19162

Disclosure Date: August 30, 2019 (last updated February 21, 2025)
A use-after-free vulnerability in the TOBESOFT XPLATFORM versions 9.1 to 9.2.2 may lead to code execution on a system running it.
Attacker Value
Unknown

CVE-2018-5197

Disclosure Date: January 02, 2019 (last updated November 27, 2024)
A vulnerability in the ExtCommon.dll user extension module version 9.2, 9.2.1, 9.2.2 of Xplatform ActiveX could allow attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command parameters. An crafted malicious parameters could cause arbitrary command to execute.
0