CVE-2024-5888
- EPSS 0.06%
- Veröffentlicht 03.03.2025 20:15:43
- Zuletzt bearbeitet 10.04.2025 20:15:21
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code i...
CVE-2024-51966
- EPSS 0.11%
- Veröffentlicht 03.03.2025 20:15:43
- Zuletzt bearbeitet 10.04.2025 20:15:21
There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended direct...
CVE-2024-51963
- EPSS 0.06%
- Veröffentlicht 03.03.2025 20:15:43
- Zuletzt bearbeitet 10.04.2025 20:15:21
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and follow that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code ...
CVE-2024-51962
- EPSS 0.06%
- Veröffentlicht 03.03.2025 20:15:43
- Zuletzt bearbeitet 13.02.2026 19:41:49
A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify column properties in a manner that could lead to SQL injection when performed by a remote authenticated user requiring elevated, non‑administrative privileges. Exploita...
CVE-2024-51960
- EPSS 0.06%
- Veröffentlicht 03.03.2025 20:15:42
- Zuletzt bearbeitet 10.04.2025 20:15:21
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code i...
CVE-2024-51956
- EPSS 0.06%
- Veröffentlicht 03.03.2025 20:15:42
- Zuletzt bearbeitet 10.04.2025 20:15:20
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code i...
CVE-2024-51957
- EPSS 0.06%
- Veröffentlicht 03.03.2025 20:15:42
- Zuletzt bearbeitet 10.04.2025 20:15:21
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code i...
CVE-2024-51958
- EPSS 0.11%
- Veröffentlicht 03.03.2025 20:15:42
- Zuletzt bearbeitet 10.04.2025 20:15:21
There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended direct...
CVE-2024-51959
- EPSS 0.06%
- Veröffentlicht 03.03.2025 20:15:42
- Zuletzt bearbeitet 10.04.2025 20:15:21
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code i...
CVE-2024-51961
- EPSS 0.08%
- Veröffentlicht 03.03.2025 20:15:42
- Zuletzt bearbeitet 10.04.2025 20:15:21
There is a local file inclusion vulnerability in ArcGIS Server 11.3 and below that may allow a remote, unauthenticated attacker to craft a URL that could potentially disclose sensitive configuration information by reading internal files from the remo...