Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown

CVE-2024-43025

Disclosure Date: September 18, 2024 (last updated October 01, 2024)
An HTML injection vulnerability in RWS MultiTrans v7.0.23324.2 and earlier allows attackers to alter the HTML-layout and possibly execute a phishing attack via a crafted payload injected into a sent e-mail.
Attacker Value
Unknown

CVE-2024-43024

Disclosure Date: September 18, 2024 (last updated September 29, 2024)
Multiple stored cross-site scripting (XSS) vulnerabilities in RWS MultiTrans v7.0.23324.2 and earlier allow attackers to execute arbitrary web scripts or HTML via a crafted payload.
Attacker Value
Unknown

CVE-2022-34268

Disclosure Date: December 25, 2023 (last updated January 04, 2024)
An issue was discovered in RWS WorldServer before 11.7.3. /clientLogin deserializes Java objects without authentication, leading to command execution on the host.
Attacker Value
Unknown

CVE-2022-34267

Disclosure Date: December 25, 2023 (last updated January 04, 2024)
An issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all authentication requirements. Arbitrary Java code can be uploaded and executed via a .jar archive to the ws-api/v2/customizations/api endpoint.
Attacker Value
Unknown

CVE-2023-40335

Disclosure Date: November 13, 2023 (last updated November 18, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Jeremy O'Connell Cleverwise Daily Quotes allows Stored XSS.This issue affects Cleverwise Daily Quotes: from n/a through 3.2.
Attacker Value
Unknown

CVE-2023-38357

Disclosure Date: August 01, 2023 (last updated October 08, 2023)
Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized access to user sessions.
Attacker Value
Unknown

CVE-2010-0613

Disclosure Date: February 11, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in viewfile.php in ARWScripts Fonts Script allows remote attackers to read arbitrary local files via directory traversal sequences in a base64-encoded f parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2008-1730

Disclosure Date: April 11, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in download.html in ARWScripts Gallery Script Lite (aka gallery-script-lite or Free Photo Gallery Site Script), as of 20080411, allows remote attackers to read arbitrary local files via directory traversal sequences in the path parameter.
0
Attacker Value
Unknown

CVE-2007-4845

Disclosure Date: September 12, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in UPLOAD/index.php in RW::Download 2.0.3 lite allow remote attackers to execute arbitrary SQL commands via the (1) dlid or (2) cid parameter.
0
Attacker Value
Unknown

CVE-2006-3517

Disclosure Date: July 11, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in stats.php in RW::Download, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.
0