Show filters
70 Total Results
Displaying 61-70 of 70
Sort by:
Attacker Value
Unknown

CVE-2020-15418

Disclosure Date: July 28, 2020 (last updated February 21, 2025)
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSRSReport class. Due to the improper restriction of XML External Entity (XXE) references, a specially crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage this vulnerability to disclose file contents in the context of SYSTEM. Was ZDI-CAN-10709.
Attacker Value
Unknown

CVE-2020-15518

Disclosure Date: July 03, 2020 (last updated February 21, 2025)
VeeamFSR.sys in Veeam Availability Suite before 10 and Veeam Backup & Replication before 10 has no device object DACL, which allows unprivileged users to achieve total control over filesystem I/O requests.
Attacker Value
Unknown

CVE-2019-19249

Disclosure Date: November 25, 2019 (last updated November 27, 2024)
Controllers/InvitationsController.cs in QueryTree before 3.0.99-beta mishandles invitations.
Attacker Value
Unknown

CVE-2015-9321

Disclosure Date: August 21, 2019 (last updated November 27, 2024)
The shortcode-factory plugin before 1.1.1 for WordPress has XSS via add_query_arg.
0
Attacker Value
Unknown

CVE-2019-14297

Disclosure Date: July 27, 2019 (last updated November 27, 2024)
Veeam ONE Reporter 9.5.0.3201 allows XSS via the Add/Edit Widget with a crafted Caption field to setDashboardWidget in CommonDataHandlerReadOnly.ashx.
0
Attacker Value
Unknown

CVE-2019-14298

Disclosure Date: July 27, 2019 (last updated November 27, 2024)
Veeam ONE Reporter 9.5.0.3201 allows XSS via a crafted Description(config) field to addDashboard or editDashboard in CommonDataHandlerReadOnly.ashx.
0
Attacker Value
Unknown

CVE-2019-11569

Disclosure Date: May 06, 2019 (last updated November 27, 2024)
Veeam ONE Reporter 9.5.0.3201 allows CSRF.
0
Attacker Value
Unknown

CVE-2015-5742

Disclosure Date: October 16, 2015 (last updated May 10, 2024)
VeeamVixProxy in Veeam Backup & Replication (B&R) before 8.0 update 3 stores local administrator credentials in log files with world-readable permissions, which allows local users to obtain sensitive information by reading the files.
0
Attacker Value
Unknown

CVE-2009-2771

Disclosure Date: August 14, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Free Arcade Script 1.3 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter to the default URI under search/.
0
Attacker Value
Unknown

CVE-2009-0731

Disclosure Date: February 24, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in pages/play.php in Free Arcade Script 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the template parameter.
0