Lucene search

K

Sourcetreesolutions Security Vulnerabilities

cve
cve

CVE-2010-3602

Cross-site scripting (XSS) vulnerability in ProfileView.aspx in mojoPortal 2.3.4.3 and 2.3.5.1 allows remote attackers to inject arbitrary web script or HTML via the User ID parameter. NOTE: some of these details are obtained from third party information.

5.9AI Score

0.003EPSS

2010-09-24 09:00 PM
21
cve
cve

CVE-2010-3603

Cross-site request forgery (CSRF) vulnerability in the file manager service (Services/FileService.ashx) in mojoPortal 2.3.4.3 and 2.3.5.1 allows remote attackers to hijack the authentication of administrators for requests that rename arbitrary files, as demonstrated by causing the user.config file ...

7.6AI Score

0.008EPSS

2010-09-24 09:00 PM
20
cve
cve

CVE-2013-5320

Cross-site scripting (XSS) vulnerability in Forums/EditPost.aspx in mojoPortal before 2.3.9.8 allows remote attackers to inject arbitrary web script or HTML via the txtSubject parameter.

5.9AI Score

0.002EPSS

2013-08-20 02:55 PM
21