Open Source Vulnerabilities
Formula Injection/CSV Injection due to Improper Neutralization of Formula Elements in CSV File in luyadev/yii-helpers
Formula Injection/CSV Injection due to Improper Neutralization of Formula Elements in CSV File in luyadev/yii-helpers
org.xwiki.platform:xwiki-platform-oldcore
XWiki Remote Code Execution
org.xwiki.platform:xwiki-platform-oldcore
XWiki Remote Code Execution
org.apache.derby:derby
Apache Derby SQL Injection
org.apache.tomcat:tomcat
Apache Tomcat Buffer Over-Read
org.apache.tomcat:tomcat, org.apache.tomcat:tomcat
Apache Tomcat XSS Vulnerability
org.apache.tomcat:tomcat/ org.apache.tomcat:tomcat
Apache Tomcat XSS Vulnerability
org.apache.tomcat:tomcat, org.apache.tomcat:tomcat, org.apache.tomcat:tomcat, org.apache.tomcat:tomcat
Cross-site scripting in Apache Tomcat
org.apache.tomcat:tomcat/ org.apache.tomcat:tomcat/ org.apache.tomcat:tomcat/ org.apache.tomcat:tomcat
Cross-site scripting in Apache Tomcat
org.eclipse.jetty:jetty-server, org.eclipse.jetty:jetty-server, org.eclipse.jetty:jetty-server, org.eclipse.jetty:jetty-server
Jetty Uses Predictable Session Identifiers
org.eclipse.jetty:jetty-server/ org.eclipse.jetty:jetty-server/ org.eclipse.jetty:jetty-server/ org.eclipse.jetty:jetty-server
Jetty Uses Predictable Session Identifiers
trac
Edgewall Trac Cross-site request forgery (CSRF) vulnerability
trac
Edgewall Trac Cross-site request forgery (CSRF) vulnerability
cakephp/cakephp
CakePHP directory traversal vulnerability allows remote attackers to read arbitrary files
cakephp/cakephp
CakePHP directory traversal vulnerability allows remote attackers to read arbitrary files
moodle/moodle
Moodle does not properly validate module instance id
moodle/moodle
Moodle does not properly validate module instance id
zope2, zope2
Zope allows remote attackers to read arbitrary files
zope2/ zope2
Zope allows remote attackers to read arbitrary files
plone
Plone allows a user to masquerade as a group
plone
Plone allows anonymous users to reset any users password through the web via Password Reset Tool
plone
Plone allows anonymous users to reset any users password through the web via Password Reset Tool
cakephp/cakephp
Cross-site scripting (XSS) vulnerability in CakePHP
cakephp/cakephp
Cross-site scripting (XSS) vulnerability in CakePHP
org.opencms:opencms-core
Alkacon OpenCms Exposes JSP Source Code
org.opencms:opencms-core
Alkacon OpenCms Exposes JSP Source Code
org.opencms:opencms-core
Alkacon OpenCMS Improper Access Control via system/workplace/views/admin/admin-main.jsp
org.opencms:opencms-core
Alkacon OpenCMS Improper Access Control via system/workplace/views/admin/admin-main.jsp
org.opencms:opencms-core
Alkacon OpenCMS Absolute Path Traversal via pathname in filePath parameter
org.opencms:opencms-core
Alkacon OpenCMS Absolute Path Traversal via pathname in filePath parameter
org.opencms:opencms-core
Alkacon OpenCms XSS via unsanitized message body
org.opencms:opencms-core
Alkacon OpenCms XSS via unsanitized message body
org.apache.tomcat:tomcat
Apache Tomcat Reveals Directories
trac
Trac reStructuredText breach of privacy and denial of service vulnerability
trac
Trac reStructuredText breach of privacy and denial of service vulnerability
zope2, zope2, zope2
Zope allows local users to read arbitrary files
zope2/ zope2/ zope2
Zope allows local users to read arbitrary files
phpsysinfo/phpsysinfo
phpSysInfo allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) sequence
phpsysinfo/phpsysinfo
phpSysInfo allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) sequence
org.mortbay.jetty:jetty
Improper Input Validation in Mortbay Jetty
org.mortbay.jetty:jetty
Improper Input Validation in Mortbay Jetty
org.mortbay.jetty:jetty
Jetty Directory Traversal Vulnerability
org.mortbay.jetty:jetty
Jetty Directory Traversal Vulnerability
org.opencms:opencms-core
Alkacon OpenCms XSS via query parameter in a search action
org.opencms:opencms-core
Alkacon OpenCms XSS via query parameter in a search action
extractor
Libextractor multiple heap-based buffer overflows
extractor
Libextractor multiple heap-based buffer overflows
plone, plone, plone
Plone allows remote users to modify arbitrary portraits
plone/ plone/ plone
Plone allows remote users to modify arbitrary portraits
struts:struts
Improper Input Validation in Apache Struts
struts:struts
Cross-site scripting in Apache Struts
struts:struts
Apache Struts vulnerable to Improper Input Validation
struts:struts
Apache Struts vulnerable to Improper Input Validation
pear/archive_tar
PEAR::Archive_Tar Directory Traversal vulnerability
pear/archive_tar
PEAR::Archive_Tar Directory Traversal vulnerability
pear/auth, pear/auth
PEAR::Auth potential authentication bypass vulnerability
pear/auth/ pear/auth
PEAR::Auth potential authentication bypass vulnerability
cherrypy
CherryPy Directory traversal vulnerability
log4net
Apache log4net format string vulnerability causes DoS
log4net
Apache log4net format string vulnerability causes DoS
geronimo:geronimo-console-standard
Apache Geronimo console 1.0 vulnerable to cross-site scripting
geronimo:geronimo-console-standard
Apache Geronimo console 1.0 vulnerable to cross-site scripting
typo3/cms
TYPO3 Reveals Sensitive Information via Direct Request to `misc/phpcheck/`
typo3/cms
TYPO3 Reveals Sensitive Information via Direct Request to `misc/phpcheck/`
org.apache.derby:derby
Apache Derby exposes user and password attributes
org.apache.derby:derby
Apache Derby exposes user and password attributes
org.apache.tomcat:tomcat
Apache Tomcat allows remote attackers to read JSP source files
org.apache.tomcat:tomcat
Apache Tomcat allows remote attackers to read JSP source files
org.apache.tomcat:tomcat
Apache Tomcat Discloses MS-DOS Pathname
org.apache.tomcat:tomcat
Apache Tomcat Discloses MS-DOS Pathname
trac
Trac HTML WikiProcessor cross-site scripting (XSS) vulnerability
trac
Trac HTML WikiProcessor cross-site scripting (XSS) vulnerability
org.opencms:opencms-core
Alkacon OpenCms XSS via username during login
org.opencms:opencms-core
Alkacon OpenCms XSS via username during login
org.apache.struts:struts-core
Apache Struts Cross-site scripting Vulnerability
org.apache.struts:struts-core
Apache Struts Cross-site scripting Vulnerability
org.mortbay.jetty:jetty
Mortbay Jetty Discloses JSP Source Code
org.mortbay.jetty:jetty
Mortbay Jetty Discloses JSP Source Code
