Absolute Poll Manager Xe
by Xigla
CVEs (5)
| CVE | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2007-4630 | 0.04 | — | 0.10 | Aug 31, 2007 | Cross-site scripting (XSS) vulnerability in xlaapmview.asp in Absolute Poll Manager XE 4.1 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | ||
| CVE-2008-6860 | 0.03 | — | 0.00 | Jul 14, 2009 | Xigla Software Absolute Poll Manager XE 4.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value. | ||
| CVE-2008-4569 | 0.03 | — | 0.00 | Oct 15, 2008 | SQL injection vulnerability in xlacomments.asp in XIGLA Software Absolute Poll Manager XE 4.1 allows remote attackers to execute arbitrary SQL commands via the p parameter. | ||
| CVE-2008-2767 | 0.00 | — | 0.00 | Jun 18, 2008 | SQL injection vulnerability in search.asp in Xigla Poll Manager XE allows remote authenticated users with administrator role privileges to execute arbitrary SQL commands via the orderby parameter. | ||
| CVE-2008-2768 | 0.00 | — | 0.00 | Jun 18, 2008 | Cross-site scripting (XSS) vulnerability in admin/search.asp in Xigla Poll Manager XE allows remote authenticated users with administrator role privileges to inject arbitrary web script or HTML via unspecified vectors ("all fields"). |
- CVE-2007-4630Aug 31, 2007risk 0.04cvss —epss 0.10
Cross-site scripting (XSS) vulnerability in xlaapmview.asp in Absolute Poll Manager XE 4.1 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
- CVE-2008-6860Jul 14, 2009risk 0.03cvss —epss 0.00
Xigla Software Absolute Poll Manager XE 4.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
- CVE-2008-4569Oct 15, 2008risk 0.03cvss —epss 0.00
SQL injection vulnerability in xlacomments.asp in XIGLA Software Absolute Poll Manager XE 4.1 allows remote attackers to execute arbitrary SQL commands via the p parameter.
- CVE-2008-2767Jun 18, 2008risk 0.00cvss —epss 0.00
SQL injection vulnerability in search.asp in Xigla Poll Manager XE allows remote authenticated users with administrator role privileges to execute arbitrary SQL commands via the orderby parameter.
- CVE-2008-2768Jun 18, 2008risk 0.00cvss —epss 0.00
Cross-site scripting (XSS) vulnerability in admin/search.asp in Xigla Poll Manager XE allows remote authenticated users with administrator role privileges to inject arbitrary web script or HTML via unspecified vectors ("all fields").