Vulnerabilities > Knowledgetree Document Management

DATE CVE VULNERABILITY TITLE RISK
2009-01-06 CVE-2008-5858 Cross-Site Scripting vulnerability in Knowledgetree Document Management Knowledgetree Document Management
Multiple cross-site scripting (XSS) vulnerabilities in KnowledgeTree before 3.5.4a allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2007-4281.
4.3
2009-01-06 CVE-2008-5857 Multiple Unspecified vulnerability in KnowledgeTree
The DropDocuments plugin in KnowledgeTree before 3.5.4a allows remote authenticated users to gain administrative privileges via a certain sequence of "browse documents" and dashboard requests.
network
low complexity
knowledgetree-document-management
6.5
2007-05-24 CVE-2007-2849 Security Bypass vulnerability in Knowledgetree Document Management Knowledgetree Document Management 3.3.3
KnowledgeTree Document Management (aka KnowledgeTree Open Source) before STABLE 3.3.7 does not require a password for an unregistered user, when the user exists in Active Directory, which allows remote attackers to log onto KTDMS without the intended authorization check.
network
low complexity
knowledgetree-document-management
critical
10.0