Gantt-Chart for Jira versions 5.5.4 and below suffer from a cross site scripting vulnerability.
dba9c39f62d06702328bfd60b00d5294682d93ffb3a9a9a32da2fcec3d90878c
Gantt-Chart for Jira versions 5.5.3 and below misses a privilege check which allows an attacker to read and write the module configuration for other users.
9df2362de6597719f21d5c1862f3e1d1ce649c17851a9656ab81b49eafc4b5ff
BKS EBK Ethernet-Buskoppler Pro versions prior to 3.01 suffer from a remote shell upload vulnerability.
34bbdc615e014059e3b04c9185a7fd91f2ae36a5796c871aaa3b732608c44564
HiScout GRC Suite versions prior to 3.1.5 suffer from a file upload vulnerability. An authenticated attacker with the permission to edit or add a "WebSiteElement" to the "content" pages is able to upload any file with any file extension to the data directory of the application. This directory is in the web root and the uploaded file is executed on the server if ".aspx" is chosen as the file extension and if the file contains aspx source code. Any commands can be executed with the permissions of the web server user on the server by exploiting this vulnerability.
0b70d18c98e2aa3b7c8228963bae5c8015cb59571383b77778ec28287f564e35