|
294551
|
8.8 |
HIGH
Network
|
cobblerd
|
cobbler
|
cobbler: Web interface lacks CSRF protection when using Django framework
|
CWE-352
Origin Validation Error
|
CVE-2011-4952
|
2024-11-21 10:33 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294552
|
7.5 |
HIGH
Network
|
mpack_project
|
mpack
|
mpack 1.6 has information disclosure via eavesdropping on mails sent by other users
|
CWE-200
Information Exposure
|
CVE-2011-4919
|
2024-11-21 10:33 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294553
|
7.5 |
HIGH
Network
|
ckeditor
|
ckeditor
|
hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackers to read private files via a direct request.
|
CWE-200
Information Exposure
|
CVE-2011-4972
|
2024-11-21 10:33 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294554
|
6.5 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.4.9 and 4.5.x before 4.5.4 does not apply proper access control on ExtDirect calls which allows remote attackers to retrieve ExtDirect endpoint services.
|
CWE-20
Improper Input Validation
|
CVE-2011-4904
|
2024-11-21 10:33 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294555
|
6.1 |
MEDIUM
Network
|
typo3
|
typo3
|
Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the RemoveXSS function.
|
CWE-79
Cross-site Scripting
|
CVE-2011-4903
|
2024-11-21 10:33 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294556
|
6.5 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to delete arbitrary files on the webserver.
|
CWE-20
Improper Input Validation
|
CVE-2011-4902
|
2024-11-21 10:33 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294557
|
6.5 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to extract arbitrary information from the TYPO3 database.
|
CWE-200
Information Exposure
|
CVE-2011-4901
|
2024-11-21 10:33 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294558
|
6.5 |
MEDIUM
Network
|
typo3 debian
|
typo3 debian_linux
|
TYPO3 before 4.5.4 allows Information Disclosure in the backend.
|
CWE-200
Information Exposure
|
CVE-2011-4900
|
2024-11-21 10:33 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294559
|
7.5 |
HIGH
Network
|
gpw_project debian
|
gpw debian_linux
|
gpw generates shorter passwords than required
|
CWE-521
Weak Password Requirements
|
CVE-2011-4931
|
2024-11-21 10:33 |
2019-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294560
|
9.8 |
CRITICAL
Network
|
mod_nss_project
|
mod_nss
|
Authentication bypass vulnerability in mod_nss 1.0.8 allows remote attackers to assume the identity of a valid user by using their certificate and entering 'password' as the password.
|
CWE-287
Improper Authentication
|
CVE-2011-4973
|
2024-11-21 10:33 |
2018-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|