Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2021-37425

Disclosure Date: August 10, 2021 (last updated February 23, 2025)
Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobiletogetherserver.cfg and then reading the certificate and private key.
Attacker Value
Unknown

CVE-2021-38490

Disclosure Date: August 10, 2021 (last updated February 23, 2025)
Altova MobileTogether Server before 7.3 SP1 allows XML exponential entity expansion, a different vulnerability than CVE-2021-37425.
Attacker Value
Unknown

CVE-2010-5272

Disclosure Date: September 07, 2012 (last updated October 05, 2023)
Untrusted search path vulnerability in Altova DatabaseSpy 2011 Enterprise Edition SP1 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .qprj file. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2010-5271

Disclosure Date: September 07, 2012 (last updated October 05, 2023)
Untrusted search path vulnerability in Altova MapForce 2011 Enterprise Edition SP1 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .mfd file. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2010-5273

Disclosure Date: September 07, 2012 (last updated October 05, 2023)
Untrusted search path vulnerability in Altova DiffDog 2011 Enterprise Edition SP1 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .dbdif file. NOTE: some of these details are obtained from third party information.
0