News


[13 total ]
PMASA-2009-6

XSS and SQL injection vulnerabilities

Affected Versions

For 2.11.x: versions before 2.11.9.6 are affected.
For 3.x: versions before 3.2.2.1 are affected.

CVE ID

CVE-2009-3696

CVE-2009-3697

PMASA-2009-5

XSS vulnerability

CVE-2009-2284

PMASA-2009-4

Insufficient output sanitizing when generating configuration file.

CVE-2009-1285

PMASA-2009-1

HTTP Response Splitting and file inclusion vulnerability.

CVE-2009-1148 CVE-2009-1149

PMASA-2009-3

Insufficient output sanitizing when generating configuration file.

CVE-2009-1151

PMASA-2009-2

Cross-site scripting on export page using cookies.

CVE-2009-1150

PMASA-2008-10

SQL injection through XSRF on several pages

CVE-2008-5621 CVE-2008-5622

PMASA-2008-9

XSS on a Designer component

CVE-2008-4775

PMASA-2008-8

XSS for Microsoft Internet Explorer on several places

CVE-2008-4326

PMASA-2008-7

Code execution vulnerability

CVE-2008-4096