Vulnerabilities > Xaraya

DATE CVE VULNERABILITY TITLE RISK
2014-02-05 CVE-2013-3639 Cross-Site Scripting vulnerability in Xaraya 2.4.0
Multiple cross-site scripting (XSS) vulnerabilities in Xaraya 2.4.0-b1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id, (2) interface, (3) name, or (4) tabmodule parameter to index.php.
network
xaraya CWE-79
4.3
2007-04-25 CVE-2007-2251 Unspecified vulnerability in Xaraya
Unspecified vulnerability in the Roles module in Xaraya 1.1.2 and earlier allows attackers to gain privileges via unspecified vectors, probably related to incorrect permission checking in xartemplates/user-view.xd.
network
low complexity
xaraya
7.5
2005-11-30 CVE-2005-3929 Directory Traversal vulnerability in Xaraya
Directory traversal vulnerability in the create function in xarMLSXML2PHPBackend.php in Xaraya 1.0 allows remote attackers to create directories and overwrite arbitrary files via ".." sequences in the module parameter to index.php.
network
low complexity
xaraya
5.0