This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Roundup-Tracker First view 2008-03-24
Product Roundup Last view 2024-07-17
Version 0.7.5 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:roundup-tracker:roundup

Activity : Overall

Related : CVE

  Date Alert Description
5.4 2024-07-17 CVE-2024-39126

Roundup before 2.4.0 allows XSS via JavaScript in PDF, XML, and SVG documents.

5.4 2024-07-17 CVE-2024-39125

Roundup before 2.4.0 allows XSS via a SCRIPT element in an HTTP Referer header.

5.4 2024-07-17 CVE-2024-39124

In Roundup before 2.4.0, classhelpers (_generic.help.html) allow XSS.

6.1 2020-01-30 CVE-2012-6133

Multiple cross-site scripting (XSS) vulnerabilities in Roundup before 1.4.20 allow remote attackers to inject arbitrary web script or HTML via the (1) @ok_message or (2) @error_message parameter to issue*.

4.3 2016-04-13 CVE-2014-6276

schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenticated users to obtain sensitive user information by viewing user details.

4.3 2014-04-11 CVE-2012-6131

Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the @action parameter to support/issue1.

4.3 2014-04-11 CVE-2012-6130

Cross-site scripting (XSS) vulnerability in the history display in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via a username, related to generating a link.

4.3 2014-04-10 CVE-2012-6132

Cross-site scripting (XSS) vulnerability in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the otk parameter.

4.3 2010-09-24 CVE-2010-2491

Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.14 allows remote attackers to inject arbitrary web script or HTML via the template argument to the /issue program.

6.4 2008-03-24 CVE-2008-1475

The xml-rpc server in Roundup 1.4.4 does not check property permissions, which allows attackers to bypass restrictions and edit or read restricted properties via the (1) list, (2) display, and (3) set methods.

4.3 2008-03-24 CVE-2008-1474

Multiple unspecified vulnerabilities in Roundup before 1.4.4 have unknown impact and attack vectors, some of which may be related to cross-site scripting (XSS).

CWE : Common Weakness Enumeration

%idName
81% (9) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')
18% (2) CWE-264 Permissions, Privileges, and Access Controls

Open Source Vulnerability Database (OSVDB)

id Description
65998 Roundup /issue cgi/client.py template Parameter XSS
43108 Roundup xmlrpc-server Property Permission Verification Failure
43107 Roundup Multiple Unspecified Issues

OpenVAS Exploits

id Description
2010-12-02 Name : Fedora Update for roundup FEDORA-2010-12290
File : nvt/gb_fedora_2010_12290_roundup_fc14.nasl
2010-09-27 Name : Fedora Update for roundup FEDORA-2010-12261
File : nvt/gb_fedora_2010_12261_roundup_fc13.nasl
2010-09-27 Name : Fedora Update for roundup FEDORA-2010-12269
File : nvt/gb_fedora_2010_12269_roundup_fc12.nasl
2009-02-17 Name : Fedora Update for roundup FEDORA-2008-9712
File : nvt/gb_fedora_2008_9712_roundup_fc8.nasl
2009-02-17 Name : Fedora Update for roundup FEDORA-2008-9734
File : nvt/gb_fedora_2008_9734_roundup_fc9.nasl
2009-02-16 Name : Fedora Update for roundup FEDORA-2008-2370
File : nvt/gb_fedora_2008_2370_roundup_fc7.nasl
2009-02-16 Name : Fedora Update for roundup FEDORA-2008-2471
File : nvt/gb_fedora_2008_2471_roundup_fc8.nasl
2008-09-24 Name : Gentoo Security Advisory GLSA 200805-21 (roundup)
File : nvt/glsa_200805_21.nasl
2008-05-12 Name : Debian Security Advisory DSA 1554-2 (roundup)
File : nvt/deb_1554_2.nasl
2008-04-30 Name : Debian Security Advisory DSA 1554-1 (roundup)
File : nvt/deb_1554_1.nasl

Nessus® Vulnerability Scanner

id Description
2016-03-04 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-3502.nasl - Type: ACT_GATHER_INFO
2015-08-24 Name: The remote Debian host is missing a security update.
File: debian_DLA-298.nasl - Type: ACT_GATHER_INFO
2010-09-24 Name: The remote Fedora host is missing a security update.
File: fedora_2010-12290.nasl - Type: ACT_GATHER_INFO
2010-09-23 Name: The remote Fedora host is missing a security update.
File: fedora_2010-12261.nasl - Type: ACT_GATHER_INFO
2010-09-23 Name: The remote Fedora host is missing a security update.
File: fedora_2010-12269.nasl - Type: ACT_GATHER_INFO
2008-11-21 Name: The remote Fedora host is missing a security update.
File: fedora_2008-9712.nasl - Type: ACT_GATHER_INFO
2008-11-21 Name: The remote Fedora host is missing a security update.
File: fedora_2008-9734.nasl - Type: ACT_GATHER_INFO
2008-05-28 Name: The remote Gentoo host is missing one or more security-related patches.
File: gentoo_GLSA-200805-21.nasl - Type: ACT_GATHER_INFO
2008-04-25 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-1554.nasl - Type: ACT_GATHER_INFO
2008-03-13 Name: The remote Fedora host is missing a security update.
File: fedora_2008-2370.nasl - Type: ACT_GATHER_INFO
2008-03-13 Name: The remote Fedora host is missing a security update.
File: fedora_2008-2471.nasl - Type: ACT_GATHER_INFO