Vulnerabilities > Gleamtech

DATE CVE VULNERABILITY TITLE RISK
2020-06-24 CVE-2020-15015 Cross-site Scripting vulnerability in Gleamtech Fileultimate 6.1.5.0
The FileExplorer component in GleamTech FileUltimate 6.1.5.0 allows XSS via an SVG document.
network
gleamtech CWE-79
4.3
2014-12-02 CVE-2014-8789 Improper Input Validation vulnerability in Gleamtech Filevista
GleamTech FileVista before 6.1 allows remote authenticated users to create arbitrary files and possibly execute arbitrary code via a crafted path in a zip archive, which is not properly handled during extraction.
network
low complexity
gleamtech CWE-20
6.5
2014-12-02 CVE-2014-8788 Information Exposure vulnerability in Gleamtech Filevista
GleamTech FileVista before 6.1 allows remote authenticated users to obtain sensitive information via a crafted path when saving a zip file, which reveals the installation path in an error message.
network
low complexity
gleamtech CWE-200
4.0