Vulnerabilities > BEA Systems > Aqualogic Interaction

DATE CVE VULNERABILITY TITLE RISK
2008-02-22 CVE-2008-0904 Information Exposure vulnerability in BEA Systems Aqualogic Interaction and Plumtree Collaboration
Unspecified vulnerability in the download servlet in BEA Plumtree Collaboration 4.1 through SP2 and AquaLogic Interaction 4.2 through MP1 allows remote attackers to read arbitrary files via a crafted URL.
network
low complexity
bea-systems CWE-200
7.8
2008-02-21 CVE-2008-0867 Cross-Site Scripting vulnerability in BEA Systems Aqualogic Interaction and Plumtree Foundation
Cross-site scripting (XSS) vulnerability in portal/server.pt in BEA AquaLogic Interaction 6.1 through MP1 and Plumtree Foundation 6.0 through SP1 allows remote attackers to inject arbitrary web script or HTML via the name parameter.
4.3