Vulnerabilities > Netcommons

DATE CVE VULNERABILITY TITLE RISK
2019-12-26 CVE-2019-6018 Cross-site Scripting vulnerability in Netcommons
Cross-site scripting vulnerability in NetCommons 3.2.2 and earlier (NetCommons3.x) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
netcommons CWE-79
4.3
2016-06-19 CVE-2016-4813 Improper Access Control vulnerability in Netcommons
NetCommons 2.4.2.1 and earlier allows remote authenticated secretariat (aka CLERK) users to gain privileges by creating a SYSTEM_ADMIN account.
network
low complexity
netcommons CWE-284
critical
9.0
2007-11-14 CVE-2007-5950 Cross-Site Scripting vulnerability in Netcommons
Cross-site scripting (XSS) vulnerability in NetCommons before 1.0.11, and 1.1.x before 1.1.2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2006-4165.
network
netcommons CWE-79
4.3
2006-08-16 CVE-2006-4165 Cross-Site Scripting vulnerability in NetCommons
Cross-site scripting (XSS) vulnerability in NetCommons 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
netcommons
6.8