Show filters
69 Total Results
Displaying 41-50 of 69
Sort by:
Attacker Value
Unknown

CVE-2018-1325

Disclosure Date: April 18, 2018 (last updated November 26, 2024)
In Apache wicket-jquery-ui <= 6.29.0, <= 7.10.1, <= 8.0.0-M9.1, JS code created in WYSIWYG editor will be executed on display.
0
Attacker Value
Unknown

CVE-2017-15719

Disclosure Date: March 12, 2018 (last updated November 26, 2024)
In Wicket jQuery UI 6.28.0 and earlier, 7.9.1 and earlier, and 8.0.0-M8 and earlier, a security issue has been discovered in the WYSIWYG editor that allows an attacker to submit arbitrary JS code to WYSIWYG editor.
0
Attacker Value
Unknown

CVE-2012-5636

Disclosure Date: October 30, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.22, 1.5.x before 1.5.10, and 6.x before 6.4.0 might allow remote attackers to inject arbitrary web script or HTML via vectors related to <script> tags in a rendered response.
0
Attacker Value
Unknown

CVE-2014-3526

Disclosure Date: October 30, 2017 (last updated November 26, 2024)
Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors involving identifiers for storing page markup for temporary user sessions.
Attacker Value
Unknown

CVE-2017-16228

Disclosure Date: October 29, 2017 (last updated November 26, 2024)
Dulwich before 0.18.5, when an SSH subprocess is used, allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-1000116, and CVE-2017-1000117.
0
Attacker Value
Unknown

CVE-2014-0043

Disclosure Date: October 03, 2017 (last updated November 08, 2023)
In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of particular classes in the classpath and thus check whether a third party library with a known security vulnerability is in use.
0
Attacker Value
Unknown

CVE-2016-6806

Disclosure Date: October 03, 2017 (last updated November 08, 2023)
Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests. The mitigation is to not only check the Origin HTTP header, but also take the Referer HTTP header into account when no Origin was provided. Furthermore, not all Wicket server side targets were subjected to the CSRF check. This was also fixed.
0
Attacker Value
Unknown

CVE-2014-7808

Disclosure Date: September 15, 2017 (last updated November 08, 2023)
Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptographic protection mechanism and predict encrypted URLs by leveraging use of CryptoMapper as the default encryption provider.
Attacker Value
Unknown

CVE-2016-6793

Disclosure Date: July 17, 2017 (last updated November 26, 2024)
The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop) and write to, move, and delete files with the permissions of DiskFileItem, and if running on a Java VM before 1.3.1, execute arbitrary code via a crafted serialized Java object.
0
Attacker Value
Unknown

CVE-2015-5347

Disclosure Date: April 12, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the getWindowOpenJavaScript function in org.apache.wicket.extensions.ajax.markup.html.modal.ModalWindow in Apache Wicket 1.5.x before 1.5.15, 6.x before 6.22.0, and 7.x before 7.2.0 might allow remote attackers to inject arbitrary web script or HTML via a ModalWindow title.
0