Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
letodms letodms vulnerabilities and exploits
(subscribe to this query)
435
VMScore
CVE-2012-4385
letodms 3.3.6 has CSRF via change password
Trilexnet Letodms 3.3.6
Debian Debian Linux 8.0
1 EDB exploit
435
VMScore
CVE-2012-4384
letodms has multiple XSS issues: Reflected XSS in Login Page, Stored XSS in Document Owner/User name, Stored XSS in Calendar
Trilexnet Letodms
Debian Debian Linux 8.0
1 EDB exploit
490
VMScore
CVE-2018-12939
A directory traversal flaw in SeedDMS (formerly LetoDMS and MyDMS) prior to 5.1.8 allows an authenticated malicious user to write to (or potentially delete) arbitrary files via a .. (dot dot) in the "op/op.UploadChunks.php" "qquuid" parameter. NOTE: this can b...
Seeddms Seeddms
578
VMScore
CVE-2018-12940
Unrestricted file upload vulnerability in "op/op.UploadChunks.php" in SeedDMS (formerly LetoDMS and MyDMS) prior to 5.1.8 allows remote malicious users to execute arbitrary code by uploading a file with an executable extension specified by the "qqfile" paramet...
Seeddms Seeddms
801
VMScore
CVE-2018-12941
This vulnerability allows remote malicious users to execute arbitrary code in SeedDMS (formerly LetoDMS and MyDMS) prior to 5.1.8 by adding a system command at the end of the "cacheDir" path and following usage of the "Clear Cache" functionality. This allows a...
Seeddms Seeddms
801
VMScore
CVE-2018-12942
SQL injection vulnerability in the "Users management" functionality in SeedDMS (formerly LetoDMS and MyDMS) prior to 5.1.8 allows authenticated malicious users to manipulate an SQL query within the application by sending additional SQL commands to the application server...
Seeddms Seeddms
383
VMScore
CVE-2018-12943
Cross-Site Scripting (XSS) vulnerability in every page that includes the "action" URL parameter in SeedDMS (formerly LetoDMS and MyDMS) prior to 5.1.8 allows remote malicious users to inject arbitrary web script or HTML via the action parameter.
Seeddms Seeddms
383
VMScore
CVE-2018-12944
Persistent Cross-Site Scripting (XSS) vulnerability in the "Categories" feature in SeedDMS (formerly LetoDMS and MyDMS) prior to 5.1.8 allows remote malicious users to inject arbitrary web script or HTML via the name field.
Seeddms Seeddms
383
VMScore
CVE-2012-4567
Multiple cross-site scripting (XSS) vulnerabilities in LetoDMS (formerly MyDMS) prior to 3.3.8 allow remote malicious users to inject arbitrary web script or HTML via unspecified parameters in (1) inc/inc.ClassUI.php or (2) out/out.DocumentNotify.php.
Letodms Project Letodms 3.3.0
Letodms Project Letodms 3.3.1
Letodms Project Letodms 3.3.2
Letodms Project Letodms 3.3.3
Letodms Project Letodms 3.3.4
Letodms Project Letodms 3.3.5
Letodms Project Letodms 3.3.6
Letodms Project Letodms 3.3.7
383
VMScore
CVE-2012-4569
Multiple cross-site scripting (XSS) vulnerabilities in out/out.UsrMgr.php in LetoDMS (formerly MyDMS) prior to 3.3.9 allow remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Letodms Project Letodms
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
TCP
CVE-2024-4577
CVE-2024-2695
CVE-2024-31870
injection
CVE-2024-3813
arbitrary code
CVE-2024-27801
CVE-2024-30120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »