6 results (0.004 seconds)

CVSS: 3.5EPSS: 0%CPEs: 3EXPL: 1

Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum eRoom 7.4.3, 7.4.4 before P19, and 7.4.4 SP1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. Múltiples vulnerabilidades de XSS en EMC Documentum eRoom 7.4.3, 7.4.4 anterior a P19, y 7.4.4 SP1 permiten a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados. EMC Documentum eRoom versions 7.4.3, 7.4.4, and 7.4.4 SP1 suffer from a stored cross site scripting vulnerability. • http://archives.neohapsis.com/archives/bugtraq/2014-06/0176.html http://packetstormsecurity.com/files/127309/EMC-Documentum-eRoom-Cross-Site-Scripting.html http://packetstormsecurity.com/files/127321/EMC-Documentum-eRoom-Stored-Cross-Site-Scripting.html http://seclists.org/fulldisclosure/2014/Jul/0 http://secunia.com/advisories/59419 http://www.securityfocus.com/archive/1/532608/100/0/threaded http://www.securitytracker.com/id/1030493 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 6EXPL: 0

Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum eRoom before 7.4.4 P11 allow remote attackers to inject arbitrary web script or HTML via a crafted URL. Múltiples vulnerabilidades de cross-site scripting (XSS) en EMC Documentum eRoom anterior a 7.4.4 P11 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de una URL manipulada. • http://archives.neohapsis.com/archives/bugtraq/2013-11/0019.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.5EPSS: 0%CPEs: 4EXPL: 0

EMC Documentum eRoom before 7.4.4 does not properly validate session cookies, which allows remote attackers to hijack or replay sessions via unspecified vectors. EMC Documentum eRoom antes de v7.4.4 no valida correctamente las cookies de sesión, lo que permite a atacantes remotos secuestrar o reproducir las sesiones a través de vectores no especificados. • http://archives.neohapsis.com/archives/bugtraq/2012-03/0057.html • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 4.3EPSS: 0%CPEs: 4EXPL: 0

Cross-site scripting (XSS) vulnerability in EMC Documentum eRoom before 7.4.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en EMC Documentum eRoom antes de v7.4.4, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de vectores no especificados. • http://archives.neohapsis.com/archives/bugtraq/2012-03/0057.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.5EPSS: 0%CPEs: 4EXPL: 0

The file-blocking feature in EMC Documentum eRoom 7.3.x and 7.4.x before 7.4.3.g does not properly restrict the uploading and opening of files with dangerous file types, which allows remote authenticated users to execute arbitrary code via an uploaded file. La funcionalidad file-blocking en EMC Documentum eRoom v7.3.x y v7.4.x antes de v7.4.3.g no restringe adecuadamente la subida y apertura de archivos peligrosos, lo que permite a usuarios autenticados remotamente ejecutar código de su elección mediante la subida de un archivo. • http://securityreason.com/securityalert/8528 http://www.securityfocus.com/archive/1/520372 • CWE-264: Permissions, Privileges, and Access Controls •