Show filters
25 Total Results
Displaying 11-20 of 25
Sort by:
Attacker Value
Unknown
CVE-2024-28853
Disclosure Date: March 27, 2024 (last updated January 16, 2025)
Ampache is a web based audio/video streaming application and file manager. Stored Cross Site Scripting (XSS) vulnerability in ampache before v6.3.1 allows a remote attacker to execute code via a crafted payload to serval parameters in the post request of /preferences.php?action=admin_update_preferences. This vulnerability is fixed in 6.3.1.
0
Attacker Value
Unknown
CVE-2024-28852
Disclosure Date: March 27, 2024 (last updated February 06, 2025)
Ampache is a web based audio/video streaming application and file manager. Ampache has multiple reflective XSS vulnerabilities,this means that all forms in the Ampache that use `rule` as a variable are not secure. For example, when querying a song, when querying a podcast, we need to use `$rule` variable. This vulnerability is fixed in 6.3.1
0
Attacker Value
Unknown
CVE-2023-0771
Disclosure Date: February 10, 2023 (last updated February 24, 2025)
SQL Injection in GitHub repository ampache/ampache prior to 5.5.7,develop.
0
Attacker Value
Unknown
CVE-2023-0606
Disclosure Date: February 01, 2023 (last updated February 24, 2025)
Cross-site Scripting (XSS) - Reflected in GitHub repository ampache/ampache prior to 5.5.7.
0
Attacker Value
Unknown
CVE-2022-4665
Disclosure Date: December 23, 2022 (last updated February 24, 2025)
Unrestricted Upload of File with Dangerous Type in GitHub repository ampache/ampache prior to 5.5.6.
0
Attacker Value
Unknown
CVE-2021-32644
Disclosure Date: June 22, 2021 (last updated February 22, 2025)
Ampache is an open source web based audio/video streaming application and file manager. Due to a lack of input filtering versions 4.x.y are vulnerable to code injection in random.php. The attack requires user authentication to access the random.php page unless the site is running in demo mode. This issue has been resolved in 4.4.3.
0
Attacker Value
Unknown
CVE-2020-15153
Disclosure Date: April 30, 2021 (last updated February 22, 2025)
Ampache before version 4.2.2 allows unauthenticated users to perform SQL injection. Refer to the referenced GitHub Security Advisory for details and a workaround. This is fixed in version 4.2.2 and the development branch.
0
Attacker Value
Unknown
CVE-2021-21399
Disclosure Date: April 13, 2021 (last updated February 22, 2025)
Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated access to Ampache using the subsonic API. To successfully make the attack you must use a username that is not part of the site to bypass the auth checks. For more details and workaround guidance see the referenced GitHub security advisory.
0
Attacker Value
Unknown
CVE-2019-12386
Disclosure Date: August 22, 2019 (last updated November 27, 2024)
An issue was discovered in Ampache through 3.9.1. A stored XSS exists in the localplay.php LocalPlay "add instance" functionality. The injected code is reflected in the instances menu. This vulnerability can be abused to force an admin to create a new privileged user whose credentials are known by the attacker.
0
Attacker Value
Unknown
CVE-2019-12385
Disclosure Date: August 22, 2019 (last updated November 27, 2024)
An issue was discovered in Ampache through 3.9.1. The search engine is affected by a SQL Injection, so any user able to perform lib/class/search.class.php searches (even guest users) can dump any data contained in the database (sessions, hashed passwords, etc.). This may lead to a full compromise of admin accounts, when combined with the weak password generator algorithm used in the lostpassword functionality.
0