Show filters
213 Total Results
Displaying 161-170 of 213
Sort by:
Attacker Value
Unknown
CVE-2018-17053
Disclosure Date: October 03, 2018 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to login request parameters, a different vulnerability than CVE-2018-17054.
0
Attacker Value
Unknown
CVE-2018-14037
Disclosure Date: September 28, 2018 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in Progress Kendo UI Editor v2018.1.221 allows remote attackers to inject arbitrary JavaScript into the DOM of the WYSIWYG editor because of the editorNS.Serializer toEditableHtml function in kendo.all.min.js. If the victim accesses the editor, the payload gets executed. Furthermore, if the payload is reflected at any other resource that does rely on the sanitisation of the editor itself, the JavaScript payload will be executed in the context of the application. This allows attackers (in the worst case) to take over user sessions.
0
Attacker Value
Unknown
CVE-2018-17056
Disclosure Date: September 28, 2018 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in ServiceStack in Progress Sitefinity CMS versions 10.2 through 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2018-17055
Disclosure Date: September 28, 2018 (last updated November 27, 2024)
An arbitrary file upload vulnerability in Progress Sitefinity CMS versions 4.0 through 11.0 related to image uploads.
0
Attacker Value
Unknown
CVE-2018-8939
Disclosure Date: May 01, 2018 (last updated August 28, 2024)
An SSRF issue was discovered in NmAPI.exe in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can submit specially crafted requests via the NmAPI executable to (1) gain unauthorized access to the WhatsUp Gold system, (2) obtain information about the WhatsUp Gold system, or (3) execute remote commands.
0
Attacker Value
Unknown
CVE-2018-8938
Disclosure Date: May 01, 2018 (last updated August 28, 2024)
A Code Injection issue was discovered in DlgSelectMibFile.asp in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can inject a specially crafted SNMP MIB file that could allow them to execute arbitrary commands and code on the WhatsUp Gold server.
0
Attacker Value
Unknown
CVE-2017-18178
Disclosure Date: February 12, 2018 (last updated November 26, 2024)
Authenticate/SWT in Progress Sitefinity 9.1 has an open redirect issue in which an authentication token is sent to the redirection target, if the target is specified using a certain %40 syntax. This is fixed in 10.1.
0
Attacker Value
Unknown
CVE-2017-18175
Disclosure Date: February 12, 2018 (last updated November 26, 2024)
Progress Sitefinity 9.1 has XSS via the Content Management Template Configuration (aka Templateconfiguration), as demonstrated by the src attribute of an IMG element. This is fixed in 10.1.
0
Attacker Value
Unknown
CVE-2017-18176
Disclosure Date: February 12, 2018 (last updated November 26, 2024)
Progress Sitefinity 9.1 has XSS via file upload, because JavaScript code in an HTML file has the same origin as the application's own code. This is fixed in 10.1.
0
Attacker Value
Unknown
CVE-2017-18179
Disclosure Date: February 12, 2018 (last updated November 26, 2024)
Progress Sitefinity 9.1 uses wrap_access_token as a non-expiring authentication token that remains valid after a password change or a session termination. Also, it is transmitted as a GET parameter. This is fixed in 10.1.
0