Vulnerabilities > Clipsoft
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-10-30 | CVE-2019-17326 | Unspecified vulnerability in Clipsoft Rexpert 1.0.0.527 ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to arbitrary file deletion by issuing a HTTP GET request with a specially crafted parameter. | 6.5 |
2019-10-30 | CVE-2019-17325 | Unrestricted Upload of File with Dangerous Type vulnerability in Clipsoft Rexpert 1.0.0.527 ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to upload arbitrary local file via the ActiveX method in RexViewerCtrl30.ocx. | 6.5 |
2019-10-30 | CVE-2019-17324 | Path Traversal vulnerability in Clipsoft Rexpert 1.0.0.527 ClipSoft REXPERT 1.0.0.527 and earlier version allows directory traversal by issuing a special HTTP POST request with ../ characters. | 6.5 |
2019-10-30 | CVE-2019-17323 | XML Injection (aka Blind XPath Injection) vulnerability in Clipsoft Rexpert 1.0.0.527 ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation and execution via report print function of rexpert viewer with modified XML document. | 8.8 |
2019-10-30 | CVE-2019-17322 | Path Traversal vulnerability in Clipsoft Rexpert 1.0.0.527 ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation via a POST request with the parameter set to the file path to be written. | 6.5 |
2019-10-30 | CVE-2019-17321 | Information Exposure vulnerability in Clipsoft Rexpert 1.0.0.527 ClipSoft REXPERT 1.0.0.527 and earlier version have an information disclosure issue. | 5.3 |