Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2012-5636
Disclosure Date: October 30, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.22, 1.5.x before 1.5.10, and 6.x before 6.4.0 might allow remote attackers to inject arbitrary web script or HTML via vectors related to <script> tags in a rendered response.
0
Attacker Value
Unknown
CVE-2013-2055
Disclosure Date: February 10, 2014 (last updated October 05, 2023)
Unspecified vulnerability in Apache Wicket 1.4.x before 1.4.23, 1.5.x before 1.5.11, and 6.x before 6.8.0 allows remote attackers to obtain sensitive information via vectors that cause raw HTML templates to be rendered without being processed and reading the information that is outside of wicket:panel markup.
0
Attacker Value
Unknown
CVE-2012-3373
Disclosure Date: September 19, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.21 and 1.5.x before 1.5.8 allows remote attackers to inject arbitrary web script or HTML via vectors involving a %00 sequence in an Ajax link URL associated with a Wicket app.
0
Attacker Value
Unknown
CVE-2012-0047
Disclosure Date: March 23, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the wicket:pageMapName parameter.
0
Attacker Value
Unknown
CVE-2012-1089
Disclosure Date: March 23, 2012 (last updated October 04, 2023)
Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-application files via a relative pathname in a URL for a Wicket resource that corresponds to a null package.
0
Attacker Value
Unknown
CVE-2011-2712
Disclosure Date: August 29, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.18, when setAutomaticMultiWindowSupport is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
0