Page 3 of 11 results (0.002 seconds)

CVSS: 4.3EPSS: 0%CPEs: 3EXPL: 0

Cross-site scripting (XSS) vulnerability in the search feature in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allows remote attackers to inject arbitrary web script or HTML via the query parameter. Vulnerabilidad de XSS en la funcionalidad de búsqueda en SeedDMS (anteriormente LetoDMS y MyDMS) anterior a 4.3.4 permite a atacantes remotos inyectar script Web o HTML arbitrarios a través del parámetro query. SeedDMS versions prior to 4.3.4 suffer from cross site scripting, remote shell upload, and path traversal vulnerabilities. • http://archives.neohapsis.com/archives/bugtraq/2014-03/0101.html http://packetstormsecurity.com/files/125726 http://secunia.com/advisories/57475 http://sourceforge.net/p/seeddms/code/ci/master/tree/CHANGELOG https://exchange.xforce.ibmcloud.com/vulnerabilities/91830 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •