Show filters
27 Total Results
Displaying 21-27 of 27
Sort by:
Attacker Value
Unknown

CVE-2020-26867

Disclosure Date: October 12, 2020 (last updated February 22, 2025)
ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the web and mobile back-end server.
Attacker Value
Unknown

CVE-2018-12989

Disclosure Date: August 03, 2018 (last updated November 27, 2024)
The report-viewing feature in Pearson VUE Certiport Console 8 and IQSystem 7 before 2018-06-26 mishandles child processes and consequently launches Internet Explorer or Microsoft Edge as Administrator, which allows local users to gain privileges.
0
Attacker Value
Unknown

CVE-2008-1273

Disclosure Date: March 10, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in imageVue 1.7 allow remote attackers to inject arbitrary web script or HTML via the path parameter to (1) popup.php, (2) test/dir2.php, (3) admin/upload.php, and (4) dirxml.php in upload/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2006-0700

Disclosure Date: February 15, 2006 (last updated February 22, 2025)
imageVue 16.1 allows remote attackers to obtain folder permission settings via a direct request to dir.php, which returns an XML document that lists folders and their permissions.
0
Attacker Value
Unknown

CVE-2006-0701

Disclosure Date: February 15, 2006 (last updated February 22, 2025)
readfolder.php in imageVue 16.1 allows remote attackers to list directories via modified path and ext parameters.
0
Attacker Value
Unknown

CVE-2006-0703

Disclosure Date: February 15, 2006 (last updated February 22, 2025)
Unspecified vulnerability in index.php in imageVue 16.1 has unknown impact, probably a cross-site scripting (XSS) vulnerability involving the query string that is not quoted when inserted into style and body tags, as demonstrated using a bgcol parameter.
0
Attacker Value
Unknown

CVE-2006-0702

Disclosure Date: February 15, 2006 (last updated February 22, 2025)
admin/upload.php in imageVue 16.1 allows remote attackers to upload arbitrary files to certain allowed folders via .. (dot dot) sequences in the path parameter. NOTE: due to the lack of details, the specific vulnerability type cannot be determined, although it might be due to directory traversal.
0