• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2019-17213

February 26, 2023 by

The WebARX plugin 1.3.0 for WordPress has unauthenticated stored XSS via the URI or the X-Forwarded-For HTTP header.

CVE-2019-17214

February 26, 2023 by

The WebARX plugin 1.3.0 for WordPress allows firewall bypass by appending &cc=1 to a URI.

CVE-2019-17108

February 26, 2023 by

Local file inclusion in brokerPerformance.php in Centreon Web before 2.8.28 allows attackers to disclose information or perform a stored XSS attack on a user.

CVE-2019-17114

February 26, 2023 by

A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allows remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/userPreregistration.jsp. The preRegistrationData parameter is vulnerable: a reflected cross-site scripting occurs immediately after a .csv file is uploaded. The malicious script is stored and can be executed again when the List Pre-Registration functionality is used.

CVE-2019-17115

February 26, 2023 by

Multiple cross-site scripting (XSS) vulnerabilities in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML that is triggered when Logs.jsp is visited. The rendered_message column is retrieved and displayed, unsanitized, on Logs.jsp. A remote attack can populate the rendered_message column with malicious values via: (1) H parameter to /wikid/servlet/com.wikidsystems.server.GetDomainHash (2) S parameter to: – /wikid/DomainData – /wikid/PreRegisterLookup – /wikid/PreRegister – /wikid/InitDevice – /wikid/servlet/InitDevice2S – /wikid/servlet/InitDevice3S – /servlet/com.wikidsystems.server.InitDevice2S – /servlet/com.wikidsystems.server.InitDevice3S – /servlet/com.wikidsystems.server.InitDevice4S – /wikid/servlet/com.wikidsystems.server.InitDevice4AES – /wikid/servlet/com.wikidsystems.server.InitDevice5AES (3) a parameter to: – /wikid/PreRegisterLookup – /wikid/InitDevice – /wikid/servlet/InitDevice2S – /wikid/servlet/InitDevice3S – /servlet/com.wikidsystems.server.InitDevice2S – /servlet/com.wikidsystems.server.InitDevice3S – /servlet/com.wikidsystems.server.InitDevice4S – /wikid/servlet/com.wikidsystems.server.InitDevice4AES – /wikid/servlet/com.wikidsystems.server.InitDevice5AES.

CVE-2019-17116

February 26, 2023 by

A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/groups.jsp. The groupName parameter is vulnerable: the reflected cross-site scripting occurs immediately after the group is created. The malicious script is stored and will be executed again whenever /WiKIDAdmin/groups.jsp is visited.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 1107
  • Go to page 1108
  • Go to page 1109
  • Go to page 1110
  • Go to page 1111
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE