Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2023-42371
Disclosure Date: September 18, 2023 (last updated October 08, 2023)
Cross Site Scripting vulnerability in Summernote Rich Text Editor v.0.8.18 and before allows a remote attacker to execute arbitrary code via a crafted script to the insert link function in the editor component.
0
Attacker Value
Unknown
CVE-2008-3367
Disclosure Date: July 30, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in RTE_popup_link.asp in Web Wiz Rich Text Editor (RTE) 3.x and 4.x before 4.03 allows remote attackers to inject arbitrary web script or HTML via the email parameter.
0
Attacker Value
Unknown
CVE-2008-0473
Disclosure Date: January 29, 2008 (last updated October 04, 2023)
RTE_popup_save_file.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to upload (1) .html and (2) .htm files via unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-0481
Disclosure Date: January 29, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the sub parameter in a save action.
0
Attacker Value
Unknown
CVE-2008-0466
Disclosure Date: January 29, 2008 (last updated October 04, 2023)
Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02, does not require authentication, which allows remote attackers to list directories and read files. NOTE: this can be leveraged for listings outside the configured directory tree by exploiting a separate directory traversal vulnerability.
0
Attacker Value
Unknown
CVE-2007-3202
Disclosure Date: June 12, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the rich text editor in Webwiz allows remote attackers to inject arbitrary web script or HTML via URL-encoded HTML composed of a frameset in which a frame has a SRC attribute pointing to a JavaScript document.
0