Search Results (22 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-19762 1 Carrier 1 Webctrl System 2024-11-21 6.1 Medium
Automated Logic Corporation (ALC) WebCTRL System 6.5 and prior allows remote attackers to execute any JavaScript code via a XSS payload for the first parameter in a GET request.
CVE-2018-8819 1 Carrier 1 Automatedlogic Webctrl 2024-11-21 N/A
An XXE issue was discovered in Automated Logic Corporation (ALC) WebCTRL Versions 6.0, 6.1 and 6.5. An unauthenticated attacker could enter malicious input to WebCTRL and a weakly configured XML parser will allow the application to disclose full file contents from the underlying web server OS via the "X-Wap-Profile" HTTP header.