Show filters
103 Total Results
Displaying 21-30 of 103
Sort by:
Attacker Value
Unknown
CVE-2020-5398
Disclosure Date: January 17, 2020 (last updated February 21, 2025)
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.
0
Attacker Value
Unknown
CVE-2019-11212
Disclosure Date: October 08, 2019 (last updated November 27, 2024)
The MDM server component of TIBCO Software Inc's TIBCO MDM contains multiple vulnerabilities that theoretically allow an authenticated user with specific roles to perform cross-site scripting (XSS) attacks. This issue affects TIBCO Software Inc.'s TIBCO MDM version 9.0.1 and prior versions; version 9.1.0.
0
Attacker Value
Unknown
CVE-2018-17789
Disclosure Date: September 20, 2019 (last updated November 27, 2024)
Prospecta Master Data Online (MDO) allows CSRF.
0
Attacker Value
Unknown
CVE-2018-17790
Disclosure Date: August 15, 2019 (last updated November 27, 2024)
Prospecta Master Data Online (MDO) 2.0 has Stored XSS.
0
Attacker Value
Unknown
CVE-2018-12319
Disclosure Date: December 04, 2018 (last updated November 27, 2024)
Denial-of-service in the login page of ASUSTOR ADM 3.1.1 allows attackers to prevent users from signing in by placing malformed text in the title.
0
Attacker Value
Unknown
CVE-2018-12307
Disclosure Date: December 04, 2018 (last updated November 27, 2024)
OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "name" POST parameter.
0
Attacker Value
Unknown
CVE-2018-12315
Disclosure Date: December 04, 2018 (last updated November 27, 2024)
Missing verification of a password in ASUSTOR ADM version 3.1.1 allows attackers to change account passwords without entering the current password.
0
Attacker Value
Unknown
CVE-2018-12313
Disclosure Date: December 04, 2018 (last updated November 27, 2024)
OS command injection in snmp.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands without authentication via the "rocommunity" URL parameter.
0
Attacker Value
Unknown
CVE-2018-12318
Disclosure Date: December 04, 2018 (last updated November 27, 2024)
Information disclosure in the SNMP settings page in ASUSTOR ADM version 3.1.1 allows attackers to obtain the SNMP password in cleartext.
0
Attacker Value
Unknown
CVE-2018-12309
Disclosure Date: December 04, 2018 (last updated November 27, 2024)
Directory Traversal in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to upload files to arbitrary locations by modifying the "path" URL parameter. NOTE: the "filename" POST parameter is covered by CVE-2018-11345.
0