Show filters
213 Total Results
Displaying 171-180 of 213
Sort by:
Attacker Value
Unknown

CVE-2017-18177

Disclosure Date: February 12, 2018 (last updated November 26, 2024)
Progress Sitefinity 9.1 has XSS via the Last name, First name, and About fields on the New User Creation Page. This is fixed in 10.1.
0
Attacker Value
Unknown

CVE-2018-5777

Disclosure Date: January 24, 2018 (last updated August 28, 2024)
An issue was discovered in Ipswitch WhatsUp Gold before 2017 Plus SP1 (17.1.1). Remote clients can take advantage of a misconfiguration in the TFTP server that could allow attackers to execute arbitrary commands on the TFTP server via unspecified vectors.
0
Attacker Value
Unknown

CVE-2018-5778

Disclosure Date: January 24, 2018 (last updated August 28, 2024)
An issue was discovered in Ipswitch WhatsUp Gold before 2017 Plus SP1 (17.1.1). Multiple SQL injection vulnerabilities are present in the legacy .ASP pages, which could allow attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2017-15883

Disclosure Date: January 08, 2018 (last updated November 26, 2024)
Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and consequently cause a denial of service on load balanced sites or gain privileges via vectors related to weak cryptography.
0
Attacker Value
Unknown

CVE-2015-9245

Disclosure Date: October 31, 2017 (last updated November 26, 2024)
Insecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to specify arbitrary URLs from which to load and execute malicious Java classes via port 20931.
0
Attacker Value
Unknown

CVE-2017-1000026

Disclosure Date: July 17, 2017 (last updated November 26, 2024)
Chef Software's mixlib-archive versions 0.3.0 and older are vulnerable to a directory traversal attack allowing attackers to overwrite arbitrary files by using ".." in tar archive entries
Attacker Value
Unknown

CVE-2017-9248

Disclosure Date: July 03, 2017 (last updated July 26, 2024)
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it easier for remote attackers to defeat cryptographic protection mechanisms, leading to a MachineKey leak, arbitrary file uploads or downloads, XSS, or ASP.NET ViewState compromise.
Attacker Value
Unknown

CVE-2017-9140

Disclosure Date: May 22, 2017 (last updated November 08, 2023)
Cross-site scripting (XSS) vulnerability in Telerik.ReportViewer.WebForms.dll in Telerik Reporting for ASP.NET WebForms Report Viewer control before R1 2017 SP2 (11.0.17.406) allows remote attackers to inject arbitrary web script or HTML via the bgColor parameter to Telerik.ReportViewer.axd.
0
Attacker Value
Unknown

CVE-2016-1000000

Disclosure Date: October 06, 2016 (last updated August 28, 2024)
Ipswitch WhatsUp Gold 16.4.1 WrFreeFormText.asp sUniqueID Parameter Blind SQL Injection
0
Attacker Value
Unknown

CVE-2015-8261

Disclosure Date: January 08, 2016 (last updated August 28, 2024)
The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized XML objects, which allows remote attackers to conduct SQL injection attacks via a crafted SOAP request.
0