VendorsAndrew Simpsonwebcollabany version
Vulnerabilities

Andrew Simpson WebCollab any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2013-2652
CRLF injection vulnerability in help/help_language.php in WebCollab 3.30 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the item parameter.
Published 2013-11-02 · Modified
4.3EPSS 0.025
CVE-2009-1454
Cross-site scripting (XSS) vulnerability in tasks.php in WebCollab before 2.50 (aka Billy Goat) allows remote attackers to inject arbitrary web script or HTML via the selection parameter in a todo action.
Published 2009-04-28 · Modified
4.3EPSS 0.012