CVE Browser
Combodo iTop: PHP Object Injection Leading to Remote Code Execution on user preferences
Combodo iTop: Reflected XSS in dashboard revert
Combodo iTop: Remote code execution using external auth variable value
Combodo iTop: Unauthenticated user can delete .readonly file
Combodo iTop: Access control bypass via OQL joins
Combodo iTop: Improper access control in ajax.render.php and ajax.document.php
Combodo iTop: Authentication bypass in exec.php allows PHP file execution
Combodo iTop: Information disclosure in ajax.render.php
Combodo iTop: Reflected XSS in foreign key search criteria
Combodo iTop: Object can be locked by a user without write permissions
Combodo iTop: Unauthorized access to object information via search operation
Combodo iTop: Reflected XSS in universal search
Combodo iTop: Reflected XSS in tag admin
Combodo iTop: Reflected XSS in synchro/synchro_import.php
Combodo iTop: Reflected XSS in dashboard save
Combodo iTop: Reflected XSS in run_query.php
Combodo iTop: Reflected XSS in /pages/ajax.render.php dashboard_id parameter
Combodo iTop: Weak secret generation for inline image
Combodo iTop: Version disclosure via login page logo
Combodo iTop: User enumeration via password reset
Combodo iTop: Insecured access to uploaded images via sniffed url
Combodo iTop vulnerable to reflected XSS in webservices/export.php
iTop admin can drop iTop database using webhooks
Combodo iTop vulnerable to IDOR with ModuleInstallation object
Combodo iTop vulnerable to reflected XSS via objection edition form error
Showing 1 to 25 CVEs · page 1 (more available)