Vulnerabilities > BEA Systems > Aqualogic Interaction
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2008-02-22 | CVE-2008-0904 | Information Exposure vulnerability in BEA Systems Aqualogic Interaction and Plumtree Collaboration Unspecified vulnerability in the download servlet in BEA Plumtree Collaboration 4.1 through SP2 and AquaLogic Interaction 4.2 through MP1 allows remote attackers to read arbitrary files via a crafted URL. | 7.8 |
2008-02-21 | CVE-2008-0867 | Cross-Site Scripting vulnerability in BEA Systems Aqualogic Interaction and Plumtree Foundation Cross-site scripting (XSS) vulnerability in portal/server.pt in BEA AquaLogic Interaction 6.1 through MP1 and Plumtree Foundation 6.0 through SP1 allows remote attackers to inject arbitrary web script or HTML via the name parameter. | 4.3 |