Show filters
602 Total Results
Displaying 431-440 of 602
Sort by:
Attacker Value
Unknown
CVE-2018-3621
Disclosure Date: November 14, 2018 (last updated November 27, 2024)
Insufficient input validation in the Intel Driver & Support Assistant before 3.6.0.4 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
0
Attacker Value
Unknown
CVE-2018-18373
Disclosure Date: October 17, 2018 (last updated November 27, 2024)
In the Schiocco "Support Board - Chat And Help Desk" plugin 1.2.3 for WordPress, a Stored XSS vulnerability has been discovered in file upload areas in the Chat and Help Desk sections via the msg parameter in a /wp-admin/admin-ajax.php sb_ajax_add_message action.
0
Attacker Value
Unknown
CVE-2018-16965
Disclosure Date: September 21, 2018 (last updated November 27, 2024)
In Zoho ManageEngine SupportCenter Plus before 8.1 Build 8109, there is HTML Injection and Stored XSS via the /ServiceContractDef.do contractName parameter.
0
Attacker Value
Unknown
CVE-2018-12148
Disclosure Date: September 12, 2018 (last updated November 27, 2024)
Privilege escalation in file permissions in Intel Driver and Support Assistant before 3.5.0.1 may allow an authenticated user to potentially execute code as administrator via local access.
0
Attacker Value
Unknown
CVE-2018-3779
Disclosure Date: August 10, 2018 (last updated November 27, 2024)
active-support ruby gem 5.2.0 could allow a remote attacker to execute arbitrary code on the system, caused by containing a malicious backdoor. An attacker could exploit this vulnerability to execute arbitrary code on the system.
0
Attacker Value
Unknown
CVE-2018-10052
Disclosure Date: April 11, 2018 (last updated November 26, 2024)
iScripts SupportDesk v4.3 has XSS via the admin/inteligentsearchresult.php txtinteligentsearch parameter.
0
Attacker Value
Unknown
CVE-2018-10051
Disclosure Date: April 11, 2018 (last updated November 26, 2024)
iScripts SupportDesk v4.3 has XSS via the staff/inteligentsearchresult.php txtinteligentsearch parameter.
0
Attacker Value
Unknown
CVE-2017-12815
Disclosure Date: March 26, 2018 (last updated November 26, 2024)
Analysis of the Bomgar Remote Support Portal JavaStart.jar Applet 52790 and earlier revealed that it is vulnerable to a path traversal vulnerability. The archive can be downloaded from a given Bomgar Remote Support Portal deployment at https://domain/api/content/JavaStart.jar and is callable from an arbitrary website using <object> and/or <appletHTML> tags. Successful exploitation results in file creation/modification/deletion in the operating system and with privileges of the user that ran the Java applet.
0
Attacker Value
Unknown
CVE-2018-1000131
Disclosure Date: March 14, 2018 (last updated November 26, 2024)
Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the function to get tickets, the parameter email in cookie was injected that can result in filter the parameter. This attack appear to be exploitable via web site, without login. This vulnerability appears to have been fixed in 9.0.3 and later.
0
Attacker Value
Unknown
CVE-2018-1214
Disclosure Date: February 12, 2018 (last updated November 26, 2024)
Dell EMC SupportAssist Enterprise version 1.1 creates a local Windows user account named "OMEAdapterUser" with a default password as part of the installation process. This unnecessary user account also remains even after an upgrade from v1.1 to v1.2. Access to the management console can be achieved by someone with knowledge of the default password. If SupportAssist Enterprise is installed on a server running OpenManage Essentials (OME), the OmeAdapterUser user account is added as a member of the OmeAdministrators group for the OME. An unauthorized person with knowledge of the default password and access to the OME web console could potentially use this account to gain access to the affected installation of OME with OmeAdministrators privileges. This is fixed in version 1.2.1.
0