Page 2 of 12 results (0.004 seconds)

CVSS: 7.5EPSS: 0%CPEs: 21EXPL: 0

18 Sep 2016 — Cloud Foundry PHP Buildpack (aka php-buildpack) before 4.3.18 and PHP Buildpack Cf-release before 242, as used in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.38 and 1.7.x before 1.7.19 and other products, place the .profile file in the htdocs directory, which might allow remote attackers to obtain sensitive information via an HTTP GET request for this file. Cloud Foundry PHP Buildpack (también conocido como php-buildpack) en versiones anteriores a 4.3.18 y PHP Buildpack Cf-release en versiones an... • https://github.com/cloudfoundry/php-buildpack/commit/e2db3ccd4812e0c0aba20720fc51789d981aba67 • CWE-254: 7PK - Security Features •

CVSS: 7.5EPSS: 0%CPEs: 13EXPL: 0

18 Sep 2016 — Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.34 and 1.7.x before 1.7.12 places 169.254.0.0/16 in the all_open Application Security Group, which might allow remote attackers to bypass intended network-connectivity restrictions by leveraging access to the 169.254.169.254 address. Pivotal Cloud Foundry (PCF) Elastic Runtime en versiones anteriores a 1.6.34 y 1.7.x en versiones anteriores a 1.7.12 sitúa 169.254.0.0/16 en el all_open Application Security Group, lo que podría permitir a atacantes remoto... • http://www.securityfocus.com/bid/92161 • CWE-254: 7PK - Security Features •