Products: 1
    Vulnerabilities: 5
    Known Exploited: 0
    0
    Critical Level Threats
    0
    High Level Threats
    4
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2014-3851

    usr/lib/cgi-bin/create_passwd_file.py in Pyplate 0.08 uses world-readable permissions for passwd.db, which allows local users to obtain the administrator password by reading this file.

    Last Modified: Apr 12, 2025
    Published: Aug 07, 2014

    CVE-2014-3852

    Pyplate 0.08 does not include the HTTPOnly flag in a Set-Cookie header for the id cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

    Last Modified: Apr 12, 2025
    Published: Aug 07, 2014

    CVE-2014-3853

    Pyplate 0.08 does not set the secure flag for the id cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

    Last Modified: Apr 12, 2025
    Published: Aug 07, 2014

    CVE-2014-3854

    Cross-site request forgery (CSRF) vulnerability in admin/addScript.py in Pyplate 0.08 allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the title parameter.

    Last Modified: Apr 12, 2025
    Published: Aug 07, 2014

    CVE-2014-3855

    Directory traversal vulnerability in download.py in Pyplate 0.08 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

    Last Modified: Apr 12, 2025
    Published: Aug 07, 2014
    Items Per Page
    Pyplate Vulnerabilities & Security CVEs | CVE-DB