Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Jam Warehouse Subscribe
Filtered by product Knowledgetree Open Source
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2012-0988 1 Jam Warehouse 1 Knowledgetree Open Source 2017-08-28 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in config/dmsDefaults.php in KnowledgeTree 3.7.0.2 and possibly earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) login.php, (2) admin.php, or (3) preferences.php.
CVE-2006-2886 1 Jam Warehouse 1 Knowledgetree Open Source 2017-07-19 4.3 MEDIUM N/A
view.php in KnowledgeTree Open Source 3.0.3 and earlier allows remote attackers to obtain the full installation path via a crafted fDocumentId parameter, which displays the path in the resulting error message. NOTE: this might be resultant from another vulnerability, since this vector also produces XSS.