Security Vulnerabilities
- CVEs Published In January 2020
Incorrect Access Control in AfficheExplorateurParam() in DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to use administrative controllers.
Path Traversal in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to browse the server filesystem.
In DIMO YellowBox CRM before 6.3.4, Path Traversal in images/Apparence (dossier=../) and servletrecuperefichier (document=../) allows an unauthenticated user to download arbitrary files from the server.
An Arbitrary File Upload issue in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to deploy a new WebApp WAR file to the Tomcat server via Path Traversal, allowing remote code execution with SYSTEM privileges.
mIRC prior to 7.22 has a message leak because chopping of outbound messages is mishandled.
Prizm Content Connect 5.1 has an Arbitrary File Upload Vulnerability
Jara 1.6 has an XSS vulnerability
websitebaker prior to and including 2.8.1 has an authentication error in backup module.
Sonoff TH 10 and 16 devices with firmware 6.6.0.21 allows XSS via the Friendly Name 1 field (after a successful login with the Web Admin Password).
Mozilla Firefox through 1.5.0.3 has a vulnerability in processing the content-length header