Quest
Quest Policy Authority FOR Unified Communications: vulnerabilidades y CVE
Quest Policy Authority FOR Unified Communications tiene 13 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-35727 | Media (5.4) | 1.3% | — | 11 ene 2021 | Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the BrowseDirs.do file via the title parameter. NOTE: This… |
| CVE-2020-35726 | Media (6.1) | 1.6% | — | 11 ene 2021 | Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the /WebCM/Applications/Reports/index.jsp file via the by parameter.… |
| CVE-2020-35725 | Media (6.1) | 1.6% | — | 11 ene 2021 | Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the /WebCM/index.jsp file via the msg parameter. NOTE: This… |
| CVE-2020-35724 | Media (5.4) | 1.2% | — | 11 ene 2021 | Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the Error.jsp file via the err parameter (or indirectly via the cpr,… |
| CVE-2020-35723 | Media (5.4) | 1.3% | — | 11 ene 2021 | Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the ReportPreview.do file via the referer parameter. NOTE: This… |
| CVE-2020-35722 | Media (6.5) | 0.69% | — | 11 ene 2021 | CSRF in Web Compliance Manager in Quest Policy Authority 8.1.2.200 allows remote attackers to force user modification/creation via a specially crafted link to the submitUser.jsp file. NOTE: This vulnerability only… |
| CVE-2020-35721 | Media (5.4) | 1.3% | — | 11 ene 2021 | Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the BrowseAssets.do file via the title parameter. NOTE: This… |
| CVE-2020-35720 | Media (5.4) | 1.2% | — | 11 ene 2021 | Stored XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to store malicious code in multiple fields (first name, last name, and logon name) when creating or modifying a user via the submitUser.jsp file.… |
| CVE-2020-35719 | Media (6.1) | 1.6% | — | 11 ene 2021 | Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the /WebCM/Applications/Search/index.jsp file via the added parameter.… |
| CVE-2020-35206 | Media (6.1) | 1.3% | — | 11 ene 2021 | Reflected XSS in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to inject malicious code into the browser via a specially crafted link to the cConn.jsp file via the ur parameter.… |
| CVE-2020-35205 | Crítica (9.8) | 1.9% | — | 11 ene 2021 | Server Side Request Forgery (SSRF) in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to scan internal ports and make outbound connections via the initFile.jsp file. NOTE: This… |
| CVE-2020-35204 | Media (6.1) | 1.3% | — | 11 ene 2021 | Reflected XSS in Quest Policy Authority version 8.1.2.200 allows attackers to inject malicious code into the browser via a specially crafted link to the PolicyAuthority/Common/FolderControl.jsp file via the unqID… |
| CVE-2020-35203 | Media (6.1) | 1.3% | — | 11 ene 2021 | Reflected XSS in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to inject malicious code into the browser via a specially crafted link to the initFile.jsp file via the msg parameter.… |