Lucene search

K

Business Manager Security Vulnerabilities

cve
cve

CVE-2009-0699

Cross-site scripting (XSS) vulnerability in pagesUTF8/auftrag_allgemeinauftrag.jsp in Plunet BusinessManager 4.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the (1) QUB and (2) Bez74 parameters.

5.4AI Score

0.003EPSS

2009-02-23 03:30 PM
32
cve
cve

CVE-2009-0700

Plunet BusinessManager 4.1 and earlier allows remote authenticated users to bypass access restrictions and (1) read sensitive Customer or Order data via a modified Pfad parameter to pagesUTF8/Sys_DirAnzeige.jsp, or (2) list sensitive Jobs via a direct request to pagesUTF8/auftrag_job.jsp.

6.3AI Score

0.008EPSS

2009-02-23 03:30 PM
20
cve
cve

CVE-2021-39332

The Business Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization found throughout the plugin which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.4.5. This a...

5.5CVSS

4.8AI Score

0.001EPSS

2021-10-15 01:15 PM
16