Vulnerabilities > Clipsoft

DATE CVE VULNERABILITY TITLE RISK
2019-10-30 CVE-2019-17326 Unspecified vulnerability in Clipsoft Rexpert 1.0.0.527
ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to arbitrary file deletion by issuing a HTTP GET request with a specially crafted parameter.
network
low complexity
clipsoft
6.5
2019-10-30 CVE-2019-17325 Unrestricted Upload of File with Dangerous Type vulnerability in Clipsoft Rexpert 1.0.0.527
ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to upload arbitrary local file via the ActiveX method in RexViewerCtrl30.ocx.
network
low complexity
clipsoft CWE-434
6.5
2019-10-30 CVE-2019-17324 Path Traversal vulnerability in Clipsoft Rexpert 1.0.0.527
ClipSoft REXPERT 1.0.0.527 and earlier version allows directory traversal by issuing a special HTTP POST request with ../ characters.
network
low complexity
clipsoft CWE-22
6.5
2019-10-30 CVE-2019-17323 XML Injection (aka Blind XPath Injection) vulnerability in Clipsoft Rexpert 1.0.0.527
ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation and execution via report print function of rexpert viewer with modified XML document.
network
low complexity
clipsoft CWE-91
8.8
2019-10-30 CVE-2019-17322 Path Traversal vulnerability in Clipsoft Rexpert 1.0.0.527
ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation via a POST request with the parameter set to the file path to be written.
network
low complexity
clipsoft CWE-22
6.5
2019-10-30 CVE-2019-17321 Information Exposure vulnerability in Clipsoft Rexpert 1.0.0.527
ClipSoft REXPERT 1.0.0.527 and earlier version have an information disclosure issue.
network
low complexity
clipsoft CWE-200
5.3