Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2014-2737
Disclosure Date: April 22, 2014 (last updated October 05, 2023)
SQL injection vulnerability in the get_active_session function in the KTAPI_UserSession class in webservice/clienttools/services/mdownload.php in KnowledgeTree 3.7.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the u parameter, related to the getFileName function.
0
Attacker Value
Unknown
CVE-2008-5858
Disclosure Date: January 06, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in KnowledgeTree before 3.5.4a allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2007-4281.
0
Attacker Value
Unknown
CVE-2008-5857
Disclosure Date: January 06, 2009 (last updated October 04, 2023)
The DropDocuments plugin in KnowledgeTree before 3.5.4a allows remote authenticated users to gain administrative privileges via a certain sequence of "browse documents" and dashboard requests.
0