|
222661
|
6.5 |
MEDIUM
Network
|
clipsoft
|
rexpert
|
ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to arbitrary file deletion by issuing a HTTP GET request with a specially crafted parameter. User interaction is required to expl…
|
NVD-CWE-noinfo
|
CVE-2019-17326
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222662
|
6.5 |
MEDIUM
Network
|
clipsoft
|
rexpert
|
ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to upload arbitrary local file via the ActiveX method in RexViewerCtrl30.ocx. That could lead to disclosure of sensitive informat…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-17325
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222663
|
6.5 |
MEDIUM
Network
|
clipsoft
|
rexpert
|
ClipSoft REXPERT 1.0.0.527 and earlier version allows directory traversal by issuing a special HTTP POST request with ../ characters. This could lead to create malicious HTML file, because they can i…
|
CWE-22
Path Traversal
|
CVE-2019-17324
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222664
|
8.8 |
HIGH
Network
|
clipsoft
|
rexpert
|
ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation and execution via report print function of rexpert viewer with modified XML document. User interaction is required to exp…
|
CWE-91
Blind XPath Injection
|
CVE-2019-17323
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222665
|
6.5 |
MEDIUM
Network
|
clipsoft
|
rexpert
|
ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation via a POST request with the parameter set to the file path to be written. This can be an executable file that is written …
|
CWE-22
Path Traversal
|
CVE-2019-17322
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222666
|
5.3 |
MEDIUM
Network
|
clipsoft
|
rexpert
|
ClipSoft REXPERT 1.0.0.527 and earlier version have an information disclosure issue. When requesting web page associated with session, could leak username via session file path of HTTP response data.…
|
CWE-200
Information Exposure
|
CVE-2019-17321
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222667
|
5.4 |
MEDIUM
Network
|
zucchetti
|
infobusiness
|
In Zucchetti InfoBusiness before and including 4.4.1, an authenticated user can inject client-side code due to improper validation of the Title field in the InfoBusiness Web Component. The payload wi…
|
CWE-79
Cross-site Scripting
|
CVE-2019-18207
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222668
|
8.8 |
HIGH
Network
|
zucchetti
|
infobusiness
|
A cross-site request forgery (CSRF) vulnerability in Zucchetti InfoBusiness before and including 4.4.1 allows arbitrary file upload.
|
CWE-352
Origin Validation Error
|
CVE-2019-18206
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222669
|
6.1 |
MEDIUM
Network
|
zucchetti
|
infobusiness
|
Multiple Reflected Cross-site Scripting (XSS) vulnerabilities exist in Zucchetti InfoBusiness before and including 4.4.1. The browsing component did not properly sanitize user input (encoded in base6…
|
CWE-79
Cross-site Scripting
|
CVE-2019-18205
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222670
|
8.8 |
HIGH
Network
|
zucchetti
|
infobusiness
|
Zucchetti InfoBusiness before and including 4.4.1 allows any authenticated user to upload .php files in order to achieve code execution.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-18204
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|