CVE-2014-9569
https://notcve.org/view.php?id=CVE-2014-9569
Multiple cross-site scripting (XSS) vulnerabilities in SAP NetWeaver Business Client (NWBC) for HTML 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) roundtrips parameter, aka SAP Security Note 2051285. Múltiples vulnerabilidades de XSS en SAP NetWeaver Business Client (NWBC) para HTML 3.0 permiten a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través del parámetro (1) title o (2) roundtrips, también conocido como SAP Security Note 2051285. • http://secunia.com/advisories/62017 http://www.securitytracker.com/id/1031509 http://www.senseofsecurity.com.au/advisories/SOS-14-005 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2014-4160
https://notcve.org/view.php?id=CVE-2014-4160
Multiple cross-site scripting (XSS) vulnerabilities in the testcanvas node in SAP NetWeaver Business Client (NWBC) allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) sap-accessibility parameter. Múltiples vulnerabilidades de XSS en el nodo testcanvas en SAP NetWeaver Business Client (NWBC) permiten a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través del parámetro (1) title o (2) sap-accessibility. • http://blog.emaze.net/2014/05/sap-multiple-vulnerabilities.html http://scn.sap.com/docs/DOC-8218 http://www.securityfocus.com/bid/67995 https://service.sap.com/sap/support/notes/1932505 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2010-4556
https://notcve.org/view.php?id=CVE-2010-4556
Stack-based buffer overflow in the SapThemeRepository ActiveX control (sapwdpcd.dll) in SAP NetWeaver Business Client allows remote attackers to execute arbitrary code via the (1) Load and (2) LoadTheme methods. Desbordamiento de búfer basado en pila en el control ActiveX SapThemeRepository (sapwdpcd.dll) en SAP NetWeaver Business Client, permite a atacantes remotos ejecutar código arbitrario a través de de los métodos (1) Load y (2) LoadTheme. • http://secunia.com/advisories/35796 http://www.securityfocus.com/bid/45396 http://www.securitytracker.com/id?1024890 http://www.vupen.com/english/advisories/2010/3239 http://www.zerodayinitiative.com/advisories/ZDI-10-290 https://exchange.xforce.ibmcloud.com/vulnerabilities/64061 https://service.sap.com/sap/support/notes/1519966 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •