Microweber
microweber
115 CVEs • 2 products
Products (2)
Click to collapseToggle
Products (2)
Click to collapse
CVEs (115)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validatio...Show more |
Code Injection in GitHub repository microweber/microweber prior to 1.3.2. |
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.1. |
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.21. |
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.21. |
An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by uploading pictures with malicious code, user.ini. |
Authentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20. |
Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform cross-site request forgery, fetch contents from same-site and redirect a user. |
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19. |
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19. |
Open Redirect in GitHub repository microweber/microweber prior to 1.2.19. |
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.18. |
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.17. |
Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, there is no email confirmation, an attacker can easily create an account...Show more |
Reflected XSS in GitHub repository microweber/microweber prior to 1.2.16. Executing JavaScript as the victim |
DOM XSS in microweber ver 1.2.15 in GitHub repository microweber/microweber prior to 1.2.16. inject arbitrary js code, deface website, steal cookie... |
XSS in /demo/module/?module=HERE in GitHub repository microweber/microweber prior to 1.2.15. Typical impact of XSS attacks. |
Reflected XSS on demo.microweber.org/demo/module/ in GitHub repository microweber/microweber prior to 1.2.15. Execute Arbitrary JavaScript as the attacked user. It's the only payload I found working, you might need to pr...Show more |
Able to create an account with long password leads to memory corruption / Integer Overflow in GitHub repository microweber/microweber prior to 1.2.12. |
The microweber application allows large characters to insert in the input field "fist & last name" which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request. in microweber/microweber in GitH...Show more |