Vulnerabilities > Boltwire

DATE CVE VULNERABILITY TITLE RISK
2023-11-07 CVE-2023-46501 Unspecified vulnerability in Boltwire 6.03
An issue in BoltWire v.6.03 allows a remote attacker to obtain sensitive information via a crafted payload to the view and change admin password function.
network
low complexity
boltwire
critical
9.1
2022-02-15 CVE-2022-24227 Cross-site Scripting vulnerability in Boltwire 7.10/8.00
A cross-site scripting (XSS) vulnerability in BoltWire v7.10 and v 8.00 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the name and lastname parameters.
network
low complexity
boltwire CWE-79
6.1
2020-01-02 CVE-2013-0737 Cross-site Scripting vulnerability in Boltwire
Cross-site scripting (XSS) vulnerability in BoltWire 3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the fieldnames parameter.
network
boltwire CWE-79
4.3
2013-10-23 CVE-2013-2651 Cross-Site Scripting vulnerability in Boltwire
Multiple cross-site scripting (XSS) vulnerabilities in BoltWire 3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) "p" or (2) content parameter to index.php.
network
boltwire CWE-79
4.3