Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2009-4877
Disclosure Date: May 26, 2010 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in WebGUI before 7.7.14 allow remote attackers to hijack the authentication of users for unspecified requests via unknown vectors.
0
Attacker Value
Unknown
CVE-2008-4798
Disclosure Date: October 30, 2008 (last updated October 04, 2023)
The loadModule function in lib/WebGUI/Asset.pm in WebGUI before 7.5.30 (stable) allows remote attackers to execute arbitrary code by uploading a Perl module and accessing it via a crafted URL.
0
Attacker Value
Unknown
CVE-2008-3503
Disclosure Date: August 06, 2008 (last updated October 04, 2023)
RSSFromParent in Plain Black WebGUI before 7.5.13 does not restrict view access to Collaboration System (CS) RSS feeds, which allows remote attackers to obtain sensitive information (CS data).
0
Attacker Value
Unknown
CVE-2008-0940
Disclosure Date: February 25, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Plain Black WebGUI before 7.4.24 allows remote attackers to inject arbitrary web script or HTML when creating a username, a different vulnerability than CVE-2007-0407.
0
Attacker Value
Unknown
CVE-2007-6487
Disclosure Date: December 20, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Plain Black WebGUI 7.4.0 through 7.4.17 allows remote authenticated users with Secondary Admin privileges to create Admin accounts, a different vulnerability than CVE-2006-0680.
0