Filtered by vendor Knowledgetree Document Management
Subscribe
Total
3 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-5858 | 1 Knowledgetree Document Management | 1 Knowledgetree Document Management | 2024-02-04 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in KnowledgeTree before 3.5.4a allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2007-4281. | |||||
CVE-2008-5857 | 1 Knowledgetree Document Management | 1 Knowledgetree Document Management | 2024-02-04 | 6.5 MEDIUM | N/A |
The DropDocuments plugin in KnowledgeTree before 3.5.4a allows remote authenticated users to gain administrative privileges via a certain sequence of "browse documents" and dashboard requests. | |||||
CVE-2007-2849 | 1 Knowledgetree Document Management | 1 Knowledgetree Document Management | 2024-02-04 | 10.0 HIGH | N/A |
KnowledgeTree Document Management (aka KnowledgeTree Open Source) before STABLE 3.3.7 does not require a password for an unregistered user, when the user exists in Active Directory, which allows remote attackers to log onto KTDMS without the intended authorization check. |