Vulnerabilities (CVE)

Filtered by vendor Sitekiosk Subscribe
Filtered by product Sitekiosk
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-6509 1 Sitekiosk 1 Sitekiosk 2024-02-28 4.1 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the skinning feature in SiteKiosk before 6.5.150 allows local users to bypass security protections and inject arbitrary web script or HTML via an ABOUT: URI, which is displayed in the title bar of the browser.
CVE-2006-6510 1 Sitekiosk 1 Sitekiosk 2024-02-28 1.7 LOW N/A
An unspecified ActiveX control in SiteKiosk before 6.5.150 is installed "safe for scripting", which allows local users to bypass security protections and read arbitrary files via certain functions.