Show filters
144 Total Results
Displaying 51-60 of 144
Sort by:
Attacker Value
Unknown
CVE-2018-20240
Disclosure Date: February 20, 2019 (last updated November 27, 2024)
The administrative linker functionality in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the href parameter.
0
Attacker Value
Unknown
CVE-2018-20241
Disclosure Date: February 20, 2019 (last updated November 27, 2024)
The Edit upload resource for a review in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the wbuser parameter.
0
Attacker Value
Unknown
CVE-2018-18733
Disclosure Date: October 29, 2018 (last updated November 27, 2024)
An XSS issue was discovered in Catfish CMS 4.8.30, related to "write source code," a similar issue to CVE-2018-13999.
0
Attacker Value
Unknown
CVE-2018-18735
Disclosure Date: October 29, 2018 (last updated November 27, 2024)
A CSRF issue was discovered in admin/Index/tiquan in catfish blog 2.0.33.
0
Attacker Value
Unknown
CVE-2018-18736
Disclosure Date: October 29, 2018 (last updated November 27, 2024)
An XSS issue was discovered in catfish blog 2.0.33, related to "write source code."
0
Attacker Value
Unknown
CVE-2018-18734
Disclosure Date: October 29, 2018 (last updated November 27, 2024)
A CSRF issue was discovered in admin/Index/addmanageuser.html in Catfish CMS 4.8.30.
0
Attacker Value
Unknown
CVE-2018-3210
Disclosure Date: October 17, 2018 (last updated November 27, 2024)
Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Java Server Faces). The supported version that is affected is 3.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GlassFish Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle GlassFish Server accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
0
Attacker Value
Unknown
CVE-2018-2911
Disclosure Date: October 17, 2018 (last updated November 27, 2024)
Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Java Server Faces). The supported version that is affected is 3.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GlassFish Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle GlassFish Server accessible data as well as unauthorized access to critical data or complete access to all Oracle GlassFish Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GlassFish Server. CVSS 3.0 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L).
0
Attacker Value
Unknown
CVE-2018-3152
Disclosure Date: October 17, 2018 (last updated November 27, 2024)
Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Administration). The supported version that is affected is 3.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GlassFish Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GlassFish Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
0
Attacker Value
Unknown
CVE-2018-13399
Disclosure Date: October 16, 2018 (last updated November 27, 2024)
The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.
0