Skip to content
Noroxi

activeweb records

4 published records for vendor activeweb.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

      The weakness classes this vendor ships most often: where to look.

      CWE

      All records

      4 records
      • CVE-2007-3013
        27Monitor

        SQL injection vulnerability in activeWeb contentserver before 5.6.2964 allows remote authenticated users with edit permission to execute arb

        MediumCVSS 6.5Proof of conceptEPSS 3%

        activeweb · contentserverJul 15, 2007

      • CVE-2007-3017
        18Monitor

        The WYSIWYG editor applet in activeWeb contentserver CMS before 5.6.2964 only filters malicious tags from articles sent to admin/applets/wys

        MediumCVSS 4.0Proof of conceptEPSS 5%

        activeweb · contentserverJul 16, 2007

      • CVE-2007-3014
        18Monitor

        Multiple cross-site scripting (XSS) vulnerabilities in activeWeb contentserver before 5.6.2964 allow remote attackers to inject arbitrary we

        MediumCVSS 4.3Proof of conceptEPSS 4%

        activeweb · contentserverJul 15, 2007

      • CVE-2007-3018
        16Monitor

        activeWeb contentserver CMS before 5.6.2964 does not limit the file-creation ability of editors who have restricted accounts, which allows t

        MediumCVSS 4.0No exploitEPSS 1%

        activeweb · contentserverJul 16, 2007