Lucene search

K

Absolute Form Processor Xe Security Vulnerabilities

cve
cve

CVE-2009-1504

Absolute Form Processor XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting the xlaAFPadmin cookie to...

7.4AI Score

0.009EPSS

2009-05-01 05:30 PM
27
cve
cve

CVE-2008-2762

SQL injection vulnerability in search.asp in Xigla Absolute Form Processor XE 4.0 allows remote authenticated administrators to execute arbitrary SQL commands via the orderby...

8AI Score

0.001EPSS

2008-06-18 10:41 PM
19
cve
cve

CVE-2008-2759

Multiple cross-site scripting (XSS) vulnerabilities in Xigla Absolute Form Processor XE 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) showfields, (2) text, and (3) submissions parameters to search.asp and the (4) name parameter to users.asp. NOTE: some of these...

5.8AI Score

0.003EPSS

2008-06-18 10:41 PM
24