Show filters
109 Total Results
Displaying 71-80 of 109
Sort by:
Attacker Value
Unknown
CVE-2021-29116
Disclosure Date: December 06, 2021 (last updated February 23, 2025)
A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server feature services versions 10.8.1 and 10.9 (only) feature services may allow a remote, unauthenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the user’s browser.
0
Attacker Value
Unknown
CVE-2021-29113
Disclosure Date: December 06, 2021 (last updated February 23, 2025)
A remote file inclusion vulnerability in the ArcGIS Server help documentation may allow a remote, unauthenticated attacker to inject attacker supplied html into a page.
0
Attacker Value
Unknown
CVE-2021-29114
Disclosure Date: December 06, 2021 (last updated February 23, 2025)
A SQL injection vulnerability in feature services provided by Esri ArcGIS Server 10.9 and below allows a remote, unauthenticated attacker to impact the confidentiality, integrity and availability of targeted services via specifically crafted queries.
0
Attacker Value
Unknown
CVE-2021-29110
Disclosure Date: July 15, 2021 (last updated February 23, 2025)
Stored cross-site scripting (XSS) issue in Esri Portal for ArcGIS may allow a remote unauthenticated attacker to pass and store malicious strings in the home application.
0
Attacker Value
Unknown
CVE-2021-29109
Disclosure Date: July 15, 2021 (last updated February 23, 2025)
A reflected XSS vulnerability in Esri Portal for ArcGIS version 10.9 and below may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the user’s browser.
0
Attacker Value
Unknown
CVE-2021-29108
Disclosure Date: July 15, 2021 (last updated February 23, 2025)
There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker who is able to intercept and modify a SAML assertion to impersonate another account (XML Signature Wrapping Attack). In addition patching, Esri also strongly recommends as best practice for SAML assertions to be signed and encrypted.
0
Attacker Value
Unknown
CVE-2021-29107
Disclosure Date: July 09, 2021 (last updated February 23, 2025)
A stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote unauthenticated attacker to pass and store malicious strings in the ArcGIS Server Manager application.
0
Attacker Value
Unknown
CVE-2021-29106
Disclosure Date: July 09, 2021 (last updated February 23, 2025)
A reflected Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server version 10.8.1 and below may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the user’s browser.
0
Attacker Value
Unknown
CVE-2021-29105
Disclosure Date: July 09, 2021 (last updated February 23, 2025)
A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server Services Directory version 10.8.1 and below may allow a remote authenticated attacker to pass and store malicious strings in the ArcGIS Services Directory.
0
Attacker Value
Unknown
CVE-2021-29104
Disclosure Date: July 09, 2021 (last updated February 23, 2025)
A stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote unauthenticated attacker to pass and store malicious strings in the ArcGIS Server Manager application.
0