description bugs

patch-1
chajer 2020-08-26 00:22:08 +02:00
parent d1e45e084e
commit a0094cb3bc
5 changed files with 5 additions and 2 deletions

View File

@ -4,7 +4,7 @@ info:
name: Nuxeo Authentication Bypass Remote Code Execution
author: madrobot
severity: high
description: Nuxeo Authentication Bypass Remote Code Execution < 103 using a SSTI
requests:
- method: GET
path:

View File

@ -4,6 +4,7 @@ info:
name: Wordpress unauthenticated stored xss
author: nadino
severity: medium
description: process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_file_name_ parameter (such as locale_file_name_en) in an authenticated theme-localization.php request to wp-admin/admin.php.
requests:
- method: POST

View File

@ -4,6 +4,7 @@ info:
name: Cross Site Scripting in Oracle Secure Global Desktop Administration Console
author: madrobot & dwisiswant0
severity: high
description: XSS exists in the Administration Console in Oracle Secure Global Desktop 4.4 20080807152602 (but was fixed in later versions including 5.4)
requests:
- method: GET

View File

@ -4,6 +4,7 @@ info:
name: Atlassian Jira WallboardServlet XSS
author: madrobot & dwisiswant0
severity: medium
description: The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the cyclePeriod parameter.
requests:
- method: GET

View File

@ -4,7 +4,7 @@ info:
name: Oracle WebCenter Sites XSS
author: madrobot
severity: medium
description: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware
requests:
- method: GET
path: