Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2020-28150
Disclosure Date: March 09, 2021 (last updated February 22, 2025)
I-Net Software Clear Reports 20.10.136 web application accepts a user-controlled input that specifies a link to an external site, and uses the user supplied data in a Redirect.
0
Attacker Value
Unknown
CVE-2020-12684
Disclosure Date: July 15, 2020 (last updated February 21, 2025)
XXE injection can occur in i-net Clear Reports 2019 19.0.287 (Designer), as used in i-net HelpDesk and other products, when XML input containing a reference to an external entity is processed by a weakly configured XML parser.
0
Attacker Value
Unknown
CVE-2020-11431
Disclosure Date: May 07, 2020 (last updated February 21, 2025)
The documentation component in i-net Clear Reports 16.0 to 19.2, HelpDesk 8.0 to 8.3, and PDFC 4.3 to 6.2 allows a remote unauthenticated attacker to read arbitrary system files and directories on the target server via Directory Traversal.
0
Attacker Value
Unknown
CVE-2005-4004
Disclosure Date: December 05, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in search.asp in MyTemplateSite 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter.
0