RSS   Vulnerabilities for 'Rich text editor'   RSS

2008-01-29
 
CVE-2008-0481

CWE-22
 

 
Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the sub parameter in a save action.

 
 
CVE-2008-0473

CWE-20
 

 
RTE_popup_save_file.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to upload (1) .html and (2) .htm files via unspecified vectors.

 

 >>> Vendor: Web wiz 3 Products
Rich text editor
Newspad
Web wiz forums


Copyright 2022, cxsecurity.com

 

Back to Top