header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Cross-Site Scripting Vulnerabilities in FatWire UpdateEngine

The FatWire UpdateEngine is prone to multiple cross-site scripting vulnerabilities. An attacker can exploit these vulnerabilities to execute arbitrary script code in the browser of a user visiting the affected site. This can lead to the theft of authentication credentials and other attacks.

Cross-Site Scripting Vulnerability in PaperThin CommonSpot Content Server

The vulnerability allows an attacker to execute arbitrary script code in the browser of an unsuspecting user by injecting malicious input through the 'url' parameter in the '/loader.cfm' page. This can lead to the theft of authentication credentials and other attacks.

IceWarp Universal WebMail Input-Validation Vulnerabilities

The IceWarp Universal WebMail is prone to multiple input-validation vulnerabilities. An attacker can exploit these issues to include arbitrary local or remote files containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible. Additionally, an attacker can exploit these issues to obtain the contents of local files.

IceWarp Universal WebMail Multiple Input-Validation Vulnerabilities

An attacker can exploit these issues to include arbitrary local or remote files containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible. Additionally, an attacker can exploit these issues to obtain the contents of local files.

Cerberus Helpdesk Multiple Vulnerabilities

Cerberus Helpdesk is prone to multiple cross-site scripting and SQL injection vulnerabilities. These issues are the result of inadequate validation of user-supplied input that will be included in site output or in SQL queries. The cross-site scripting vulnerability may permit a remote attacker to steal cookie-based authentication credentials from legitimate users. Successful exploitation of SQL injection vulnerabilities could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

Multiple Cross-Site Scripting and SQL Injection Vulnerabilities in Cerberus Helpdesk

Cerberus Helpdesk is prone to multiple cross-site scripting and SQL injection vulnerabilities. These issues are the result of inadequate validation of user-supplied input that will be included in site output or in SQL queries.The cross-site scripting vulnerability may permit a remote attacker to steal cookie-based authentication credentials from legitimate users. Successful exploitation of SQL injection vulnerabilities could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

Oracle Application Server Discussion Forum Portlet Multiple Vulnerabilities

The Oracle Application Server Discussion Forum Portlet is affected by multiple remote vulnerabilities. The application is prone to a cross-site scripting vulnerability and multiple HTML injection vulnerabilities. It is also vulnerable to a source code disclosure vulnerability. An attacker can exploit these vulnerabilities to execute arbitrary script code, inject malicious HTML, and disclose sensitive source code information.

Recent Exploits: