Show filters
161 Total Results
Displaying 61-70 of 161
Sort by:
Attacker Value
Unknown
CVE-2015-7679
Disclosure Date: February 10, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in Ipswitch MOVEit Mobile before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the query string to mobile/.
0
Attacker Value
Unknown
CVE-2015-7677
Disclosure Date: February 10, 2016 (last updated November 25, 2024)
The MOVEitISAPI service in Ipswitch MOVEit DMZ before 8.2 provides different error messages depending on whether a FileID exists, which allows remote authenticated users to enumerate FileIDs via the X-siLock-FileID parameter in a download action to MOVEitISAPI/MOVEitISAPI.dll.
0
Attacker Value
Unknown
CVE-2015-7675
Disclosure Date: February 10, 2016 (last updated November 25, 2024)
The "Send as attachment" feature in Ipswitch MOVEit DMZ before 8.2 and MOVEit Mobile before 1.2.2 allow remote authenticated users to bypass authorization and read uploaded files via a valid FileID in the (1) serverFileIds parameter to mobile/sendMsg or (2) arg01 parameter to human.aspx.
0
Attacker Value
Unknown
CVE-2015-7680
Disclosure Date: February 10, 2016 (last updated November 25, 2024)
Ipswitch MOVEit DMZ before 8.2 provides different error messages for authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of SOAP requests to machine.aspx.
0
Attacker Value
Unknown
CVE-2015-7392
Disclosure Date: October 05, 2015 (last updated October 05, 2023)
Heap-based buffer overflow in the parse_string function in libs/esl/src/esl_json.c in FreeSWITCH before 1.4.23 and 1.6.x before 1.6.2 allows remote attackers to execute arbitrary code via a trailing \u in a json string to cJSON_Parse.
0
Attacker Value
Unknown
CVE-2014-9737
Disclosure Date: July 06, 2015 (last updated October 05, 2023)
Open redirect vulnerability in the Language Switcher Dropdown module 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a block.
0
Attacker Value
Unknown
CVE-2011-4722
Disclosure Date: December 28, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in the TFTP Server 1.0.0.24 in Ipswitch WhatsUp Gold allows remote attackers to read arbitrary files via a .. (dot dot) in the Filename field of an RRQ operation.
0
Attacker Value
Unknown
CVE-2014-3878
Disclosure Date: June 05, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the web client interface in Ipswitch IMail Server 12.3 and 12.4, possibly before 12.4.1.15, allow remote attackers to inject arbitrary web script or HTML via (1) the Name field in an add new contact action in the Contacts section or unspecified vectors in (2) an Add Group task in the Contacts section, (3) an add new event action in the Calendar section, or (4) the Task section.
0
Attacker Value
Unknown
CVE-2013-2238
Disclosure Date: September 30, 2013 (last updated October 05, 2023)
Multiple buffer overflows in the switch_perform_substitution function in switch_regex.c in FreeSWITCH 1.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to the index and substituted variables.
0
Attacker Value
Unknown
CVE-2012-3449
Disclosure Date: August 07, 2012 (last updated October 04, 2023)
Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/pki/controllerca/incoming/ and (2) /var/lib/openvswitch/pki/switchca/incoming/, which allows local users to delete and overwrite arbitrary files.
0