A vulnerability was found in O2OA up to 10.0-410. It has been rated as problematic. Affected is an unknown function of the file /x_query_assemble_designer/jaxrs/importmodel of the component Personal Profile Page. Performing manipulation of the argument description/applicationName/queryName results in cross site scripting.
This vulnerability is known as CVE-2025-9737. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."
A vulnerability was found in O2OA up to 10.0-410. It has been declared as problematic. This impacts an unknown function of the file /x_query_assemble_designer/jaxrs/statement of the component Personal Profile Page. Such manipulation of the argument description/queryName leads to cross site scripting.
This vulnerability is traded as CVE-2025-9736. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."
A vulnerability was found in O2OA up to 10.0-410. It has been classified as problematic. This affects an unknown function of the file /x_query_assemble_designer/jaxrs/table of the component Personal Profile Page. This manipulation of the argument description/applicationName/queryName causes cross site scripting.
This vulnerability appears as CVE-2025-9735. The attack may be initiated remotely. In addition, an exploit is available.
The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."
A vulnerability was found in O2OA up to 10.0-410 and classified as problematic. The impacted element is an unknown function of the file /x_query_assemble_designer/jaxrs/stat of the component Personal Profile Page. The manipulation of the argument name/alias/description/applicationName results in cross site scripting.
This vulnerability is reported as CVE-2025-9734. The attack can be launched remotely. Moreover, an exploit is present.
The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."
A vulnerability has been found in WM Downloader up to 3.1.2.2 and classified as critical. The affected element is an unknown function. The manipulation leads to buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is documented as CVE-2010-10017. The attack needs to be performed locally. Additionally, an exploit exists.
A vulnerability, which was classified as critical, was found in BS.Player Free and Pro Editions up to 2.57. Impacted is an unknown function. Executing manipulation can lead to buffer overflow.
This vulnerability is registered as CVE-2010-10016. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability classified as critical was found in Sunway ForceControl up to 6.1 SP3. This vulnerability affects unknown code of the component SNMP NetDBServer Service. Such manipulation leads to stack-based buffer overflow.
This vulnerability is listed as CVE-2011-10032. The attack may be performed from remote. In addition, an exploit is available.
A vulnerability classified as critical has been found in ContentKeeper/Impero Web Appliance up to 125.9. This affects an unknown part of the component File Handler. This manipulation causes unrestricted upload.
This vulnerability is tracked as CVE-2009-20011. The attack is possible to be carried out remotely. Moreover, an exploit is present.
It is recommended to upgrade the affected component.
A vulnerability described as critical has been identified in Dogfood CRM up to 2.0.10. Affected by this issue is some unknown functionality of the file spell.php. The manipulation of the argument data results in os command injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is identified as CVE-2009-20010. The attack can be executed remotely. Additionally, an exploit exists.
A vulnerability marked as critical has been reported in Raxnet/Ian Berry Cacti. Affected by this vulnerability is an unknown functionality of the file graph_view.php of the component GET Parameter Handler. The manipulation of the argument graph_start leads to os command injection.
This vulnerability is referenced as CVE-2005-10004. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
It is suggested to upgrade the affected component.
A vulnerability labeled as critical has been found in Apache Friends XAMPP up to 1.7.3. Affected is an unknown function of the file /webdav/ of the component WebDAV Service. Executing manipulation can lead to unrestricted upload.
The identification of this vulnerability is CVE-2012-10062. The attack may be launched remotely. Furthermore, there is an exploit available.