Vulnerabilities (CVE)

Filtered by vendor Xceedium Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-4665 1 Xceedium 1 Xsuite 2018-06-19 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in ajax_cmd.php in Xceedium Xsuite 2.4.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the fileName parameter.
CVE-2015-4666 1 Xceedium 1 Xsuite 2018-06-19 5.0 MEDIUM N/A
Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier allows remote attackers to read arbitrary files via a ....// (quadruple dot double slash) in the logFile parameter.