Show filters
27 Total Results
Displaying 21-27 of 27
Sort by:
Attacker Value
Unknown
CVE-2020-26867
Disclosure Date: October 12, 2020 (last updated February 22, 2025)
ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the web and mobile back-end server.
0
Attacker Value
Unknown
CVE-2018-12989
Disclosure Date: August 03, 2018 (last updated November 27, 2024)
The report-viewing feature in Pearson VUE Certiport Console 8 and IQSystem 7 before 2018-06-26 mishandles child processes and consequently launches Internet Explorer or Microsoft Edge as Administrator, which allows local users to gain privileges.
0
Attacker Value
Unknown
CVE-2008-1273
Disclosure Date: March 10, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in imageVue 1.7 allow remote attackers to inject arbitrary web script or HTML via the path parameter to (1) popup.php, (2) test/dir2.php, (3) admin/upload.php, and (4) dirxml.php in upload/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2006-0700
Disclosure Date: February 15, 2006 (last updated February 22, 2025)
imageVue 16.1 allows remote attackers to obtain folder permission settings via a direct request to dir.php, which returns an XML document that lists folders and their permissions.
0
Attacker Value
Unknown
CVE-2006-0701
Disclosure Date: February 15, 2006 (last updated February 22, 2025)
readfolder.php in imageVue 16.1 allows remote attackers to list directories via modified path and ext parameters.
0
Attacker Value
Unknown
CVE-2006-0703
Disclosure Date: February 15, 2006 (last updated February 22, 2025)
Unspecified vulnerability in index.php in imageVue 16.1 has unknown impact, probably a cross-site scripting (XSS) vulnerability involving the query string that is not quoted when inserted into style and body tags, as demonstrated using a bgcol parameter.
0
Attacker Value
Unknown
CVE-2006-0702
Disclosure Date: February 15, 2006 (last updated February 22, 2025)
admin/upload.php in imageVue 16.1 allows remote attackers to upload arbitrary files to certain allowed folders via .. (dot dot) sequences in the path parameter. NOTE: due to the lack of details, the specific vulnerability type cannot be determined, although it might be due to directory traversal.
0