Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2023-37272

Disclosure Date: July 13, 2023 (last updated October 08, 2023)
JS7 is an Open Source Job Scheduler. Users specify file names when uploading files holding user-generated documentation for JOC Cockpit. Specifically crafted file names allow an XSS attack to inject code that is executed with the browser. Risk of the vulnerability is considered high for branch 1.13 of JobScheduler (JS1). The vulnerability does not affect branch 2.x of JobScheduler (JS7) for releases after 2.1.0. The vulnerability is resolved with release 1.13.19.
Attacker Value
Unknown

CVE-2020-12712

Disclosure Date: June 11, 2020 (last updated February 21, 2025)
A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 and 1.13 allows attackers to decrypt the user/password that is optionally stored with a user's profile.
Attacker Value
Unknown

CVE-2020-6856

Disclosure Date: February 06, 2020 (last updated February 21, 2025)
An XML External Entity (XEE) vulnerability exists in the JOC Cockpit component of SOS JobScheduler 1.12 and 1.13.2 allows attackers to read files from the server via an entity declaration in any of the XML documents that are used to specify the run-time settings of jobs and orders.
Attacker Value
Unknown

CVE-2020-6855

Disclosure Date: February 06, 2020 (last updated February 21, 2025)
A large or infinite loop vulnerability in the JOC Cockpit component of SOS JobScheduler 1.11 and 1.13.2 allows attackers to parameterize housekeeping jobs in a way that exhausts system resources and results in a denial of service.
Attacker Value
Unknown

CVE-2020-6854

Disclosure Date: February 05, 2020 (last updated February 21, 2025)
A cross-site scripting (XSS) vulnerability in the JOC Cockpit component of SOS JobScheduler 1.11 and 1.13.2 allows attackers to inject arbitrary web script or HTML via JSON properties available from the REST API.
Attacker Value
Unknown

CVE-2014-5392

Disclosure Date: September 23, 2014 (last updated October 05, 2023)
XML External Entity (XXE) vulnerability in JobScheduler before 1.6.4246 and 7.x before 1.7.4241 allows remote attackers to cause a denial of service and read arbitrary files or directories via a request containing an XML external entity declaration in conjunction with an entity reference.
0
Attacker Value
Unknown

CVE-2014-5393

Disclosure Date: September 11, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in the JobScheduler Operations Center (JOC) in SOS JobScheduler before 1.6.4246 and 1.7.x before 1.7.4241 allows remote authenticated users with the info permission to read arbitrary files in the webroot via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-5391

Disclosure Date: September 11, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the JobScheduler Operations Center (JOC) in SOS JobScheduler before 1.6.4246 and 1.7.x before 1.7.4241 allows remote attackers to inject arbitrary web script or HTML via the hash property (location.hash).
0
Attacker Value
Unknown

CVE-2006-5929

Disclosure Date: November 16, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in firepjs.php in Phpjobscheduler 3.0 allows remote attackers to execute arbitrary PHP code via a URL in the installed_config_file parameter. NOTE: the provenance of this information is unknown; details are obtained from third party sources.
0
Attacker Value
Unknown

CVE-2006-5928

Disclosure Date: November 16, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Phpjobscheduler 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the installed_config_file parameter to (1) add-modify.php, (2) delete.php, (3) modify.php, and (4) phpjobscheduler.php.
0