Page 2 of 8 results (0.003 seconds)

CVSS: 7.5EPSS: 0%CPEs: 6EXPL: 1

Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala. Dino antes del 10-09-2019, no comprueba la autorización de inserción de lista en el archivo module/roster/module.vala. • http://www.openwall.com/lists/oss-security/2019/09/12/5 https://github.com/dino/dino/commit/dd33f5f949248d87d34f399e8846d5ee5b8823d9 https://gultsch.de/dino_multiple.html https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5TMGQ5Q6QMIFG4NVUWMOWW3GIPGWQZVF https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WZBNQAOBWTIOKNO4PIYNX624ACGUXSXQ https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YUBM7GDZBB6MZZALDWYRAPNV6HJNLNMC h • CWE-862: Missing Authorization •

CVSS: 7.5EPSS: 0%CPEs: 6EXPL: 0

Dino before 2019-09-10 does not properly check the source of an MAM message in module/xep/0313_message_archive_management.vala. Dino antes del 10-09-2019, no comprueba correctamente la fuente de un mensaje MAM en el archivo module/xep/0313_message_archive_management.vala. • http://www.openwall.com/lists/oss-security/2019/09/12/5 https://github.com/dino/dino/commit/307f16cc86dd2b95aa02ab8a85110e4a2d5e7363 https://gultsch.de/dino_multiple.html https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5TMGQ5Q6QMIFG4NVUWMOWW3GIPGWQZVF https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WZBNQAOBWTIOKNO4PIYNX624ACGUXSXQ https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YUBM7GDZBB6MZZALDWYRAPNV6HJNLNMC h • CWE-346: Origin Validation Error •

CVSS: 6.8EPSS: 1%CPEs: 1EXPL: 2

Directory traversal vulnerability in index.php in D-iscussion Board 3.01 allows remote attackers to read arbitrary files via a .. (dot dot) in the topic parameter. Vulnerabilidad de salto de directorio en index.php de D-iscussion Board 3.01 permite a atacantes remotos leer ficheros de su elección a través de .. (punto punto) en el parámetro topic. • https://www.exploit-db.com/exploits/6430 http://secunia.com/advisories/31808 http://securityreason.com/securityalert/4249 http://www.securityfocus.com/bid/31135 https://exchange.xforce.ibmcloud.com/vulnerabilities/45063 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •