VYPR

Rich Text Editor

by Webwiz

CVEs (5)

  • CVE-2008-0481Jan 29, 2008
    risk 0.03cvss epss 0.04

    Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the sub parameter in a save action.

  • CVE-2008-0473Jan 29, 2008
    risk 0.03cvss epss 0.03

    RTE_popup_save_file.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to upload (1) .html and (2) .htm files via unspecified vectors.

  • CVE-2008-0466Jan 29, 2008
    risk 0.03cvss epss 0.05

    Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02, does not require authentication, which allows remote attackers to list directories and read files. NOTE: this can be leveraged for listings outside the…

  • CVE-2008-3367Jul 30, 2008
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in RTE_popup_link.asp in Web Wiz Rich Text Editor (RTE) 3.x and 4.x before 4.03 allows remote attackers to inject arbitrary web script or HTML via the email parameter.

  • CVE-2007-3202Jun 12, 2007
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the rich text editor in Webwiz allows remote attackers to inject arbitrary web script or HTML via URL-encoded HTML composed of a frameset in which a frame has a SRC attribute pointing to a JavaScript document.