Lucene search

K

Taxweb Security Vulnerabilities

cve
cve

CVE-2013-6019

Cross-site scripting (XSS) vulnerability in Tyler Technologies TaxWeb 3.13.3.1 allows remote attackers to inject arbitrary web script or HTML via the accountNum parameter to an unspecified...

5.9AI Score

0.002EPSS

2022-10-03 04:14 PM
18
cve
cve

CVE-2013-6020

passwordRequestPOST.jsp in Tyler Technologies TaxWeb 3.13.3.1 sends different HTTP status codes for invalid password-recovery requests depending on whether the user account exists, which allows remote attackers to enumerate account names via a series of requests to the (1) Assessor, (2) Recorder,.....

6.7AI Score

0.003EPSS

2022-10-03 04:14 PM
21
cve
cve

CVE-2013-6018

Cross-site request forgery (CSRF) vulnerability in login.jsp in Tyler Technologies TaxWeb 3.13.3.1 allows remote attackers to hijack the authentication of arbitrary users for requests that change a...

7.4AI Score

0.001EPSS

2022-10-03 04:14 PM
16
cve
cve

CVE-2013-6285

The search component in the Treasurer application in Tyler Technologies TaxWeb 3.13.3.1 allows remote attackers to obtain sensitive query-structure information via an invalid search request, a different vulnerability than...

6.3AI Score

0.003EPSS

2022-10-03 04:14 PM
24