Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2024-42499
Disclosure Date: November 15, 2024 (last updated November 15, 2024)
Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in FitNesse releases prior to 20241026. If this vulnerability is exploited, an attacker may be able to know whether a file exists at a specific path, and/or obtain some part of the file contents under specific conditions.
0
Attacker Value
Unknown
CVE-2024-39610
Disclosure Date: November 15, 2024 (last updated November 21, 2024)
Cross-site scripting vulnerability exists in FitNesse releases prior to 20241026. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using the product.
0
Attacker Value
Unknown
CVE-2024-28039
Disclosure Date: March 18, 2024 (last updated April 01, 2024)
Improper restriction of XML external entity references vulnerability exists in FitNesse all releases, which allows a remote unauthenticated attacker to obtain sensitive information, alter data, or cause a denial-of-service (DoS) condition.
0
Attacker Value
Unknown
CVE-2024-28128
Disclosure Date: March 18, 2024 (last updated April 01, 2024)
Cross-site scripting vulnerability exists in FitNesse releases prior to 20220319, which may allow a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is using the product and accessing a link with a specially crafted certain parameter.
0
Attacker Value
Unknown
CVE-2024-28125
Disclosure Date: March 18, 2024 (last updated October 10, 2024)
FitNesse all releases allows a remote authenticated attacker to execute arbitrary OS commands. Note: A contributor of FitNesse has claimed that this is not a vulnerability but a product specification and this is currently under further investigation.
0
Attacker Value
Unknown
CVE-2024-23604
Disclosure Date: March 18, 2024 (last updated April 01, 2024)
Cross-site scripting vulnerability exists in FitNesse all releases, which may allow a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is using the product and accessing a link with specially crafted multiple parameters.
0
Attacker Value
Unknown
CVE-2020-2175
Disclosure Date: April 07, 2020 (last updated February 21, 2025)
Jenkins FitNesse Plugin 1.31 and earlier does not correctly escape report contents before showing them on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users able to control the XML input files processed by the plugin.
0
Attacker Value
Unknown
CVE-2020-2120
Disclosure Date: February 12, 2020 (last updated February 21, 2025)
Jenkins FitNesse Plugin 1.30 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.
0
Attacker Value
Unknown
CVE-2014-1216
Disclosure Date: April 22, 2014 (last updated October 05, 2023)
FitNesse Wiki 20131110, 20140201, and earlier allows remote attackers to execute arbitrary commands by defining a COMMAND_PATTERN and TEST_RUNNER in the pageContent parameter when editing a page.
0