Page 2 of 11 results (0.039 seconds)
CVSS: 6.1EPSS: 0%CPEs: 3EXPL: 1
CVE-2014-2280 – SeedDMS XSS / Traversal / Shell Upload
https://notcve.org/view.php?id=CVE-2014-2280
14 Mar 2014 — Cross-site scripting (XSS) vulnerability in the search feature in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allows remote attackers to inject arbitrary web script or HTML via the query parameter. Vulnerabilidad de XSS en la funcionalidad de búsqueda en SeedDMS (anteriormente LetoDMS y MyDMS) anterior a 4.3.4 permite a atacantes remotos inyectar script Web o HTML arbitrarios a través del parámetro query. SeedDMS versions prior to 4.3.4 suffer from cross site scripting, remote shell upload, and path t... • https://packetstorm.news/files/id/125726 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •