Show filters
717 Total Results
Displaying 351-360 of 717
Sort by:
Attacker Value
Unknown

CVE-2013-3215

Disclosure Date: January 29, 2020 (last updated February 21, 2025)
vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.
Attacker Value
Unknown

CVE-2013-3212

Disclosure Date: January 28, 2020 (last updated February 21, 2025)
vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execute local script code.
Attacker Value
Unknown

CVE-2013-3214

Disclosure Date: January 28, 2020 (last updated February 21, 2025)
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
Attacker Value
Unknown

CVE-2019-6036

Disclosure Date: January 27, 2020 (last updated February 21, 2025)
Cross-site scripting vulnerability in F-RevoCRM 6.0 to F-RevoCRM 6.5 patch6 (version 6 series) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Attacker Value
Unknown

CVE-2020-7996

Disclosure Date: January 26, 2020 (last updated February 21, 2025)
htdocs/user/passwordforgotten.php in Dolibarr 10.0.6 allows XSS via the Referer HTTP header.
Attacker Value
Unknown

CVE-2020-7995

Disclosure Date: January 26, 2020 (last updated February 21, 2025)
The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts.
Attacker Value
Unknown

CVE-2020-7994

Disclosure Date: January 26, 2020 (last updated February 21, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 10.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) label[libelle] parameter to the /htdocs/admin/dict.php?id=3 page; the (2) name[constname] parameter to the /htdocs/admin/const.php?mainmenu=home page; the (3) note[note] parameter to the /htdocs/admin/dict.php?id=10 page; the (4) zip[MAIN_INFO_SOCIETE_ZIP] or email[mail] parameter to the /htdocs/admin/company.php page; the (5) url[defaulturl], field[defaultkey], or value[defaultvalue] parameter to the /htdocs/admin/defaultvalues.php page; the (6) key[transkey] or key[transvalue] parameter to the /htdocs/admin/translation.php page; or the (7) [main_motd] or [main_home] parameter to the /htdocs/admin/ihm.php page.
Attacker Value
Unknown

CVE-2019-14766

Disclosure Date: January 21, 2020 (last updated February 21, 2025)
Path Traversal in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to browse the server filesystem.
Attacker Value
Unknown

CVE-2019-14767

Disclosure Date: January 21, 2020 (last updated February 21, 2025)
In DIMO YellowBox CRM before 6.3.4, Path Traversal in images/Apparence (dossier=../) and servletrecuperefichier (document=../) allows an unauthenticated user to download arbitrary files from the server.
Attacker Value
Unknown

CVE-2019-14765

Disclosure Date: January 21, 2020 (last updated November 27, 2024)
Incorrect Access Control in AfficheExplorateurParam() in DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to use administrative controllers.