
CVE-2008-5325
https://notcve.org/view.php?id=CVE-2008-5325
05 Dec 2008 — Multiple cross-site scripting (XSS) vulnerabilities in CQ Web in IBM Rational ClearQuest 7.0.0 before 7.0.0.4 and 7.0.1 before 7.0.1.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. Múltiples vulnerabilidades de secuencias de ejecución de comandos en sitios cruzados en CQ Web en IBM Rational ClearQuest v7.0.0 anterior a la v7.0.0.4 y 7.0.1 anterior a la v7.0.1.3 permitiría a atacantes remotos inyectar secuencias de comandos web o HTML a su elección a través de vectore... • http://secunia.com/advisories/32847 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2008-5330 – IBM Rational ClearCase 7/8 - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2008-5330
05 Dec 2008 — Multiple cross-site scripting (XSS) vulnerabilities in the web interface in ClearCase RWP server in IBM Rational ClearCase 7.0.0 before 7.0.0.4, and 7.0.1.1-RATL-RCC-IFIX02 and possibly other 7.0.1 versions before 7.0.1.3, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO of a URI associated with a VOB page. Múltiples vulnerabilidades de secuencias de ejecución de comandos en sitios cruzados en la interfaz web de ClearCase RWP server en IBM Rational ClearCase v7.0.0 anterior a ... • https://www.exploit-db.com/exploits/32631 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2008-5324
https://notcve.org/view.php?id=CVE-2008-5324
05 Dec 2008 — Multiple cross-site scripting (XSS) vulnerabilities in CQ Web in IBM Rational ClearQuest 2007 before 2007D and 2008 before 2008B allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. Múltiples vulnerabilidades de secuencias de ejecución de comandos en sitios cruzados en CQ Web en IBM Rational ClearQuest v2007 anteriores a v2007D y v2008 anteriores a v2008B permitiría a atacantes remotos inyectar secuencias de código web o HTML a través de vectores no específicos. • http://www-01.ibm.com/support/docview.wss?uid=swg1PK69316 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2008-3550
https://notcve.org/view.php?id=CVE-2008-3550
08 Aug 2008 — The CQWeb login page in IBM Rational ClearQuest 7.0.1 allows remote attackers to obtain potentially sensitive information (page source code) via a combination of ?script? and ?/script? sequences in the id field, possibly related to a cross-site scripting (XSS) vulnerability. • http://www-1.ibm.com/support/docview.wss?uid=swg1PK68332 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2007-4592 – IBM Rational ClearQuest 7.0 - Multiple Cross-Site Scripting Vulnerabilities
https://notcve.org/view.php?id=CVE-2007-4592
20 Mar 2008 — Multiple cross-site scripting (XSS) vulnerabilities in the web interface for IBM Rational ClearQuest before 2003.06.16 Patch 2008A, 7.0.0.2_iFix01, and 7.0.1.1_iFix01 allow remote attackers to inject arbitrary web script or HTML via the (1) contextid, (2) username, (3) userNameVal, and (4) schema parameters to the login component. Múltiples vulnerabilidades de tipo cross-site scripting (XSS) en la interfaz web para IBM Rational ClearQuest versiones anteriores a 2003.06.16 Parche 2008A, 7.0.0.2_iFix01 y 7.0.... • https://www.exploit-db.com/exploits/31438 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2008-1288
https://notcve.org/view.php?id=CVE-2008-1288
11 Mar 2008 — IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 might allow local or remote attackers to obtain sensitive information about users by reading user cookies. IBM Rational ClearQuest 7.0.1.1 y 7.0.0.2 podrían permitir a atacantes locales o remotos obtener información sensible sobre usuarios mediante la lectura de las cookies de los usuarios. • http://secunia.com/advisories/29280 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2008-1287
https://notcve.org/view.php?id=CVE-2008-1287
11 Mar 2008 — IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to enumerate usernames. IBM Rational ClearQuest versiones 7.0.1.1.1 y 7.0.0.0.2, genera diferentes mensajes de error dependiendo de si el nombre de usuario es válido o no válido, lo que permite a los atacantes remotos enumerar los nombres de usuario. • http://secunia.com/advisories/29280 • CWE-16: Configuration •

CVE-2007-5090
https://notcve.org/view.php?id=CVE-2007-5090
26 Sep 2007 — Unspecified vulnerability in IBM Rational ClearQuest (CQ), when a Microsoft SQL Server or an IBM DB2 database is used, allows attackers to corrupt data via unspecified vectors. Vulnerabilidad sin especificar en el IBM Rational ClearQuest (CQ), cuando se utilizan las bases de datos Microsoft SQL Server o IBM DB2, permite a atacantes remotos corromper los datos a través de vectores sin especificar. • http://osvdb.org/40598 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2007-4368 – IBM Rational ClearQuest - Web Authentication Bypass / SQL Injection
https://notcve.org/view.php?id=CVE-2007-4368
15 Aug 2007 — SQL injection vulnerability in /main in IBM Rational ClearQuest (CQ) Web 7.0.0.0-IFIX02 and 7.0.0.1 allows remote attackers to execute arbitrary SQL commands via the username parameter in a GenerateMainFrame command. Una vulnerabilidad de inyección SQL en /main en IBM Rational ClearQuest (CQ) Web versiones 7.0.0.0.0-IFIX02 y 7.0.0.0.1, permite a atacantes remotos ejecutar comandos SQL arbitrarios por medio del parámetro username en un comando GenerateMainFrame. • https://www.exploit-db.com/exploits/4286 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2007-1468
https://notcve.org/view.php?id=CVE-2007-1468
16 Mar 2007 — Cross-site scripting (XSS) vulnerability in IBM Rational ClearQuest (CQ) Web 7.0.0.0 allows remote attackers to inject arbitrary web script or HTML via an attachment to a defect log entry. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el IBM Rational ClearQuest (CQ) Web 7.0.0.0 permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección mediante un adjunto en la entrada de log por defecto. • http://osvdb.org/34346 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •