Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2012-6130
Disclosure Date: April 11, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the history display in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via a username, related to generating a link.
0
Attacker Value
Unknown
CVE-2012-6131
Disclosure Date: April 11, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the @action parameter to support/issue1.
0
Attacker Value
Unknown
CVE-2012-6132
Disclosure Date: April 10, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the otk parameter.
0
Attacker Value
Unknown
CVE-2010-2491
Disclosure Date: September 24, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.14 allows remote attackers to inject arbitrary web script or HTML via the template argument to the /issue program.
0
Attacker Value
Unknown
CVE-2009-2737
Disclosure Date: August 11, 2009 (last updated October 04, 2023)
The EditCSVAction function in cgi/actions.py in Roundup 1.2 before 1.2.1, 1.4 through 1.4.6, and possibly other versions does not properly check permissions, which allows remote authenticated users with edit or create privileges for a class to modify arbitrary items within that class, as demonstrated by editing all queries, modifying settings, and adding roles to users.
0
Attacker Value
Unknown
CVE-2008-1474
Disclosure Date: March 24, 2008 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in Roundup before 1.4.4 have unknown impact and attack vectors, some of which may be related to cross-site scripting (XSS).
0
Attacker Value
Unknown
CVE-2008-1475
Disclosure Date: March 24, 2008 (last updated October 04, 2023)
The xml-rpc server in Roundup 1.4.4 does not check property permissions, which allows attackers to bypass restrictions and edit or read restricted properties via the (1) list, (2) display, and (3) set methods.
0