|
294121
|
7.5 |
HIGH
Network
|
ckeditor
|
ckeditor
|
hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackers to read private files via a direct request.
|
CWE-200
Information Exposure
|
CVE-2011-4972
|
2024-11-21 10:33 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294122
|
6.5 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.4.9 and 4.5.x before 4.5.4 does not apply proper access control on ExtDirect calls which allows remote attackers to retrieve ExtDirect endpoint services.
|
CWE-20
Improper Input Validation
|
CVE-2011-4904
|
2024-11-21 10:33 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294123
|
6.1 |
MEDIUM
Network
|
typo3
|
typo3
|
Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the RemoveXSS function.
|
CWE-79
Cross-site Scripting
|
CVE-2011-4903
|
2024-11-21 10:33 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294124
|
6.5 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to delete arbitrary files on the webserver.
|
CWE-20
Improper Input Validation
|
CVE-2011-4902
|
2024-11-21 10:33 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294125
|
6.5 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to extract arbitrary information from the TYPO3 database.
|
CWE-200
Information Exposure
|
CVE-2011-4901
|
2024-11-21 10:33 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294126
|
6.5 |
MEDIUM
Network
|
typo3 debian
|
typo3 debian_linux
|
TYPO3 before 4.5.4 allows Information Disclosure in the backend.
|
CWE-200
Information Exposure
|
CVE-2011-4900
|
2024-11-21 10:33 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294127
|
7.5 |
HIGH
Network
|
gpw_project debian
|
gpw debian_linux
|
gpw generates shorter passwords than required
|
CWE-521
Weak Password Requirements
|
CVE-2011-4931
|
2024-11-21 10:33 |
2019-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294128
|
9.8 |
CRITICAL
Network
|
mod_nss_project
|
mod_nss
|
Authentication bypass vulnerability in mod_nss 1.0.8 allows remote attackers to assume the identity of a valid user by using their certificate and entering 'password' as the password.
|
CWE-287
Improper Authentication
|
CVE-2011-4973
|
2024-11-21 10:33 |
2018-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294129
|
9.8 |
CRITICAL
Network
|
ibm
|
websphere_application_server
|
The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 does …
|
CWE-254
7PK - Security Features
|
CVE-2011-4889
|
2024-11-21 10:33 |
2018-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294130
|
6.1 |
MEDIUM
Network
|
bsuite_project
|
bsuite
|
Multiple cross-site scripting (XSS) vulnerabilities in ui_stats.php in the bSuite plugin before 5 alpha 3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s or …
|
CWE-79
Cross-site Scripting
|
CVE-2011-4955
|
2024-11-21 10:33 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|