Show filters
717 Total Results
Displaying 351-360 of 717
Sort by:
Attacker Value
Unknown
CVE-2013-3215
Disclosure Date: January 29, 2020 (last updated February 21, 2025)
vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.
0
Attacker Value
Unknown
CVE-2013-3212
Disclosure Date: January 28, 2020 (last updated February 21, 2025)
vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execute local script code.
0
Attacker Value
Unknown
CVE-2013-3214
Disclosure Date: January 28, 2020 (last updated February 21, 2025)
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
0
Attacker Value
Unknown
CVE-2019-6036
Disclosure Date: January 27, 2020 (last updated February 21, 2025)
Cross-site scripting vulnerability in F-RevoCRM 6.0 to F-RevoCRM 6.5 patch6 (version 6 series) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2020-7996
Disclosure Date: January 26, 2020 (last updated February 21, 2025)
htdocs/user/passwordforgotten.php in Dolibarr 10.0.6 allows XSS via the Referer HTTP header.
0
Attacker Value
Unknown
CVE-2020-7995
Disclosure Date: January 26, 2020 (last updated February 21, 2025)
The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts.
0
Attacker Value
Unknown
CVE-2020-7994
Disclosure Date: January 26, 2020 (last updated February 21, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 10.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) label[libelle] parameter to the /htdocs/admin/dict.php?id=3 page; the (2) name[constname] parameter to the /htdocs/admin/const.php?mainmenu=home page; the (3) note[note] parameter to the /htdocs/admin/dict.php?id=10 page; the (4) zip[MAIN_INFO_SOCIETE_ZIP] or email[mail] parameter to the /htdocs/admin/company.php page; the (5) url[defaulturl], field[defaultkey], or value[defaultvalue] parameter to the /htdocs/admin/defaultvalues.php page; the (6) key[transkey] or key[transvalue] parameter to the /htdocs/admin/translation.php page; or the (7) [main_motd] or [main_home] parameter to the /htdocs/admin/ihm.php page.
0
Attacker Value
Unknown
CVE-2019-14766
Disclosure Date: January 21, 2020 (last updated February 21, 2025)
Path Traversal in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to browse the server filesystem.
0
Attacker Value
Unknown
CVE-2019-14767
Disclosure Date: January 21, 2020 (last updated February 21, 2025)
In DIMO YellowBox CRM before 6.3.4, Path Traversal in images/Apparence (dossier=../) and servletrecuperefichier (document=../) allows an unauthenticated user to download arbitrary files from the server.
0
Attacker Value
Unknown
CVE-2019-14765
Disclosure Date: January 21, 2020 (last updated November 27, 2024)
Incorrect Access Control in AfficheExplorateurParam() in DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to use administrative controllers.
0