|
224061
|
6.5 |
MEDIUM
Network
|
clipsoft
|
rexpert
|
ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to upload arbitrary local file via the ActiveX method in RexViewerCtrl30.ocx. That could lead to disclosure of sensitive informat…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-17325
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224062
|
6.5 |
MEDIUM
Network
|
clipsoft
|
rexpert
|
ClipSoft REXPERT 1.0.0.527 and earlier version allows directory traversal by issuing a special HTTP POST request with ../ characters. This could lead to create malicious HTML file, because they can i…
|
CWE-22
Path Traversal
|
CVE-2019-17324
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224063
|
8.8 |
HIGH
Network
|
clipsoft
|
rexpert
|
ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation and execution via report print function of rexpert viewer with modified XML document. User interaction is required to exp…
|
CWE-91
Blind XPath Injection
|
CVE-2019-17323
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224064
|
6.5 |
MEDIUM
Network
|
clipsoft
|
rexpert
|
ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation via a POST request with the parameter set to the file path to be written. This can be an executable file that is written …
|
CWE-22
Path Traversal
|
CVE-2019-17322
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224065
|
5.3 |
MEDIUM
Network
|
clipsoft
|
rexpert
|
ClipSoft REXPERT 1.0.0.527 and earlier version have an information disclosure issue. When requesting web page associated with session, could leak username via session file path of HTTP response data.…
|
CWE-200
Information Exposure
|
CVE-2019-17321
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224066
|
5.4 |
MEDIUM
Network
|
zucchetti
|
infobusiness
|
In Zucchetti InfoBusiness before and including 4.4.1, an authenticated user can inject client-side code due to improper validation of the Title field in the InfoBusiness Web Component. The payload wi…
|
CWE-79
Cross-site Scripting
|
CVE-2019-18207
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224067
|
8.8 |
HIGH
Network
|
zucchetti
|
infobusiness
|
A cross-site request forgery (CSRF) vulnerability in Zucchetti InfoBusiness before and including 4.4.1 allows arbitrary file upload.
|
CWE-352
Origin Validation Error
|
CVE-2019-18206
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224068
|
6.1 |
MEDIUM
Network
|
zucchetti
|
infobusiness
|
Multiple Reflected Cross-site Scripting (XSS) vulnerabilities exist in Zucchetti InfoBusiness before and including 4.4.1. The browsing component did not properly sanitize user input (encoded in base6…
|
CWE-79
Cross-site Scripting
|
CVE-2019-18205
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224069
|
8.8 |
HIGH
Network
|
zucchetti
|
infobusiness
|
Zucchetti InfoBusiness before and including 4.4.1 allows any authenticated user to upload .php files in order to achieve code execution.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-18204
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224070
|
9.8 |
CRITICAL
Network
|
trendmicro
|
officescan apex_one worry-free_business_security
|
A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5, 10.0) may allow an attacker to bypass authentication and log on to an affecte…
|
CWE-22
Path Traversal
|
CVE-2019-18189
|
2024-11-21 13:32 |
2019-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|