Show filters
461 Total Results
Displaying 221-230 of 461
Sort by:
Attacker Value
Unknown
Orchestration Designer Runtime Config XSS
Disclosure Date: September 21, 2018 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could result in malicious content being returned to the user. Affected versions of Avaya Aura Orchestration Designer include all versions up to 7.2.1.
0
Attacker Value
Unknown
Improper access controls in IP Office one-X Portal
Disclosure Date: September 12, 2018 (last updated November 27, 2024)
A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arbitrary files on the system. Affected versions of Avaya IP Office include 9.1 through 9.1 SP12, 10.0 through 10.0 SP7, and 10.1 through 10.1 SP2.
0
Attacker Value
Unknown
CVE-2018-16551
Disclosure Date: September 05, 2018 (last updated November 27, 2024)
LavaLite 5.5 has XSS via a /edit URI, as demonstrated by client/job/job/Zy8PWBekrJ/edit.
0
Attacker Value
Unknown
CVE-2018-15528
Disclosure Date: August 21, 2018 (last updated November 27, 2024)
Reflected Cross-Site Scripting exists in the Java System Solutions SSO plugin 4.0.13.1 for BMC MyIT. A remote attacker can abuse this issue to inject client-side scripts into the "select_sso()" function. The payload is triggered when the victim opens a prepared /ux/jss-sso/arslogin?[XSS] link and then clicks the "Login" button.
0
Attacker Value
Unknown
Some Navarino Infinity functions placed in the URL can bypass any authenticatio…
Disclosure Date: July 24, 2018 (last updated November 08, 2023)
Some Navarino Infinity functions, up to version 2.2, placed in the URL can bypass any authentication mechanism leading to an information leak.
0
Attacker Value
Unknown
Navarino Infinity web interface up to version 2.2 exposes an unauthenticated sc…
Disclosure Date: July 24, 2018 (last updated November 08, 2023)
Navarino Infinity web interface up to version 2.2 exposes an unauthenticated script that is prone to blind sql injection. If successfully exploited the user can get info from the underlying postgresql database that could lead into to total compromise of the product. The said script is available with no authentication.
0
Attacker Value
Unknown
Navarino Infinity web interface up to version 2.2 is prone to session fixation …
Disclosure Date: July 24, 2018 (last updated November 08, 2023)
Navarino Infinity is prone to session fixation attacks. The server accepts the session ID as a GET parameter which can lead to bypassing the two factor authentication in some installations. This could lead to phishing attacks that can bypass the two factor authentication that is present in some installations.
0
Attacker Value
Unknown
CVE-2018-13145
Disclosure Date: July 04, 2018 (last updated November 08, 2023)
The mintToken function of a smart contract implementation for JavaSwapTest (JST), an Ethereum token, has an integer overflow.
0
Attacker Value
Unknown
CVE-2018-12432
Disclosure Date: June 14, 2018 (last updated November 26, 2024)
JavaMelody through 1.60.0 has XSS via the counter parameter in a clear_counter action to the /monitoring URI.
0
Attacker Value
Unknown
CVE-2018-9159
Disclosure Date: March 31, 2018 (last updated November 26, 2024)
In Spark before 2.7.2, a remote attacker can read unintended static files via various representations of absolute or relative pathnames, as demonstrated by file: URLs and directory traversal sequences. NOTE: this product is unrelated to Ignite Realtime Spark.
0