cbcvebase.

Activeweb Contentserver vulnerabilities

4 known vulnerabilities affecting activeweb/contentserver.

Total CVEs
4
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2007-3013P4MEDIUMCVSS 6.5PoC≤ 5.6.29292007-07-15
CVE-2007-3013 [MEDIUM] CVE-2007-3013: SQL injection vulnerability in activeWeb contentserver before 5.6.2964 allows remote authenticated u SQL injection vulnerability in activeWeb contentserver before 5.6.2964 allows remote authenticated users with edit permission to execute arbitrary SQL commands via the id parameter to admin/picture/picture_real_edit.asp, and probably other unspecified vectors.
nvd
CVE-2007-3017P4MEDIUMCVSS 4.0PoC≤ 5.6.29292007-07-17
CVE-2007-3017 [MEDIUM] CVE-2007-3017: The WYSIWYG editor applet in activeWeb contentserver CMS before 5.6.2964 only filters malicious tags The WYSIWYG editor applet in activeWeb contentserver CMS before 5.6.2964 only filters malicious tags from articles sent to admin/applets/wysiwyg/rendereditor.asp, which allows remote authenticated users to inject arbitrary JavaScript via a request to admin/worklist/worklist_edit.asp.
nvd
CVE-2007-3014P4MEDIUMCVSS 4.3PoC≤ 5.6.29292007-07-15
CVE-2007-3014 [MEDIUM] CVE-2007-3014: Multiple cross-site scripting (XSS) vulnerabilities in activeWeb contentserver before 5.6.2964 allow Multiple cross-site scripting (XSS) vulnerabilities in activeWeb contentserver before 5.6.2964 allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) errors/rights.asp or (2) errors/transaction.asp, or (3) the name of a MIME type (mimetype).
nvd
CVE-2007-3018P4MEDIUMCVSS 4.0≤ 5.6.29292007-07-17
CVE-2007-3018 [MEDIUM] CVE-2007-3018: activeWeb contentserver CMS before 5.6.2964 does not limit the file-creation ability of editors who activeWeb contentserver CMS before 5.6.2964 does not limit the file-creation ability of editors who have restricted accounts, which allows these editors to create files in arbitrary directories.
nvd
Activeweb Contentserver vulnerabilities | cvebase