SolarWinds Serv-U FTP Server versions through 15.2.1 do not correctly sanitize and validate the user-supplied directory names, allowing malicious users to create directories that when clicked on (in the breadcrumb menu) will trigger cross site scripting payloads.
7b4d92cd96ecbdf9bbfd42665ba4d3b8
SolarWinds Serv-U File Server versions through 15.2.1 do not correctly validate path information, allowing the disclosure of files and directories outside of the user's home directory via a specially crafted GET request.
bcff8e686a6d68a1e71f68016c03b076
OpenAsset Digital Asset Management suffers from an authenticated blind remote SQL injection vulnerability.
104a24c90358f7b176c601947844d418
OpenAsset Digital Asset Management suffers from a cross site request forgery vulnerability.
4ef799a57a5bebf1c7686ee9e8bb591b
OpenAsset Digital Asset Management was found to provide several endpoints which allowed for unauthenticated data retrieval in a CSV format. Vulnerable versions include 12.0.19 (Cloud) and 11.2.1 (On-premise).
dcbdd080e561d84592ffec066c3a8472
The OpenAsset Digital Asset Management web application suffers from multiple reflected and persistent cross site scripting vulnerabilities. Vulnerable versions include 12.0.19 (Cloud) and 11.2.1 (On-premise).
35b3d6bf27bfcacaa597e0ed89c5cc54
The OpenAsset Digital Asset Management web application allowed for spoofing of IP addresses by using X-Forwarded-For header. By default, the web application would allow all traffic in for 127.0.0.1, in order to prevent users from accidentally blocking themselves. Vulnerable versions include 12.0.19 (Cloud) and 11.2.1 (On-premise).
b1d09f4404b1268792fe1602be620242
WordPress DirectoriesPro plugin version 1.3.45 suffers from multiple cross site scripting vulnerabilities.
ea91243869739ae676c39bebb79d51c4
WordPress NAB Transact WooCommerce plugin version 2.1.0 suffers from a payment bypass vulnerability.
580b8c08be425934c55c29d9872fc490
WordPress WooCommerce Advanced Order Export plugin version 3.1.3 suffers from a cross site scripting vulnerability.
4d813f18afcf977d88533a85efc4c0bf