CVE-2017-12649
XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted title or summary that is mishandled in the Web Content Display.
Read MoreXSS exists in Liferay Portal before 7.0 CE GA4 via a crafted title or summary that is mishandled in the Web Content Display.
Read MoreSQL injection exists in Quest KACE Asset Management Appliance 6.4.120822 through 7.2, Systems Management Appliance 6.4.120822 through 7.2.101, and K1000 as a Service 7.0 through 7.2.
Read MoreXSS exists in Liferay Portal before 7.0 CE GA4 via a Knowledge Base article title.
Read MoreXSS exists in Liferay Portal before 7.0 CE GA4 via an invalid portletId.
Read MoreXSS exists in Liferay Portal before 7.0 CE GA4 via a login name, password, or e-mail address.
Read More