|
295561
|
4.8 |
MEDIUM
Network
|
f5 debian
|
nginx debian_linux
|
nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)
|
CWE-20
Improper Input Validation
|
CVE-2011-4968
|
2024-11-21 10:33 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295562
|
7.5 |
HIGH
Network
|
openpegasus redhat
|
tog-pegasus enterprise_linux
|
tog-Pegasus has a package hash collision DoS vulnerability
|
CWE-20
Improper Input Validation
|
CVE-2011-4967
|
2024-11-21 10:33 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295563
|
7.8 |
HIGH
Local
|
cobblerd
|
cobbler
|
cobbler has local privilege escalation via the use of insecure location for PYTHON_EGG_CACHE
|
CWE-269
Improper Privilege Management
|
CVE-2011-4954
|
2024-11-21 10:33 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295564
|
8.8 |
HIGH
Network
|
cobblerd
|
cobbler
|
cobbler: Web interface lacks CSRF protection when using Django framework
|
CWE-352
Origin Validation Error
|
CVE-2011-4952
|
2024-11-21 10:33 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295565
|
7.5 |
HIGH
Network
|
mpack_project
|
mpack
|
mpack 1.6 has information disclosure via eavesdropping on mails sent by other users
|
CWE-200
Information Exposure
|
CVE-2011-4919
|
2024-11-21 10:33 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295566
|
7.5 |
HIGH
Network
|
ckeditor
|
ckeditor
|
hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackers to read private files via a direct request.
|
CWE-200
Information Exposure
|
CVE-2011-4972
|
2024-11-21 10:33 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295567
|
6.5 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.4.9 and 4.5.x before 4.5.4 does not apply proper access control on ExtDirect calls which allows remote attackers to retrieve ExtDirect endpoint services.
|
CWE-20
Improper Input Validation
|
CVE-2011-4904
|
2024-11-21 10:33 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295568
|
6.1 |
MEDIUM
Network
|
typo3
|
typo3
|
Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the RemoveXSS function.
|
CWE-79
Cross-site Scripting
|
CVE-2011-4903
|
2024-11-21 10:33 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295569
|
6.5 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to delete arbitrary files on the webserver.
|
CWE-20
Improper Input Validation
|
CVE-2011-4902
|
2024-11-21 10:33 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295570
|
6.5 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to extract arbitrary information from the TYPO3 database.
|
CWE-200
Information Exposure
|
CVE-2011-4901
|
2024-11-21 10:33 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|