CVE-2024-51944
- EPSS 0.06%
- Veröffentlicht 03.03.2025 20:15:40
- Zuletzt bearbeitet 10.04.2025 20:15:19
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code i...
CVE-2024-51942
- EPSS 0.06%
- Veröffentlicht 03.03.2025 20:15:40
- Zuletzt bearbeitet 10.04.2025 20:15:19
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code i...
CVE-2024-10904
- EPSS 0.06%
- Veröffentlicht 03.03.2025 20:15:39
- Zuletzt bearbeitet 10.04.2025 20:15:18
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code i...
CVE-2023-25848
- EPSS 0.1%
- Veröffentlicht 25.08.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 07:50:18
ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthorized attacker may submit a crafted query that may result in a low severity information disclosure issue. The information disclosed...
CVE-2023-25841
- EPSS 0.65%
- Veröffentlicht 21.07.2023 19:15:10
- Zuletzt bearbeitet 10.04.2025 19:15:56
There is a stored Cross-site Scripting vulnerability in Esri ArcGIS Server versions 11.0 and below on Windows and Linux platforms that may allow a remote, unauthenticated attacker to create crafted content which when clicked could potentially execute...
CVE-2023-25840
- EPSS 0.18%
- Veröffentlicht 21.07.2023 19:15:10
- Zuletzt bearbeitet 10.04.2025 19:15:56
There is a Cross-site Scripting vulnerability in ArcGIS Server in versions 11.1 and below that may allow a remote, authenticated attacker to create a crafted link which onmouseover wont execute but could potentially render an image in the victims bro...
CVE-2022-38202
- EPSS 0.75%
- Veröffentlicht 28.12.2022 17:15:10
- Zuletzt bearbeitet 21.11.2024 07:16:03
There is a path traversal vulnerability in Esri ArcGIS Server versions 10.9.1 and below. Successful exploitation may allow a remote, unauthenticated attacker traverse the file system to access files outside of the intended directory on ArcGIS Server....
CVE-2022-38200
- EPSS 0.34%
- Veröffentlicht 25.10.2022 17:15:55
- Zuletzt bearbeitet 21.11.2024 07:16:02
A cross site scripting vulnerability exists in some map service configurations of ArcGIS Server versions 10.8.1 and 10.7.1. Specifically crafted web requests can execute arbitrary JavaScript in the context of the victim's browser.
CVE-2022-38199
- EPSS 0.2%
- Veröffentlicht 25.10.2022 17:15:55
- Zuletzt bearbeitet 21.11.2024 07:16:02
A remote file download issue can occur in some capabilities of Esri ArcGIS Server web services that may in some edge cases allow a remote, unauthenticated attacker to induce an unsuspecting victim to launch a process in the victim's PATH environment....
CVE-2022-38198
- EPSS 0.53%
- Veröffentlicht 25.10.2022 17:15:55
- Zuletzt bearbeitet 21.11.2024 07:16:02
There is a reflected cross site scripting issue in the Esri ArcGIS Server services directory versions 10.9.1 and below that may allow a remote, unauthenticated attacker to convince a user to click on a crafted link which could potentially execute arb...