Show filters
112 Total Results
Displaying 101-110 of 112
Sort by:
Attacker Value
Unknown

CVE-2015-6567

Disclosure Date: April 14, 2017 (last updated November 26, 2024)
Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not validate the parameter "filename" properly. Exploitation requires a registered user who has access to upload functionality.
0
Attacker Value
Unknown

CVE-2017-6076

Disclosure Date: February 24, 2017 (last updated November 26, 2024)
In versions of wolfSSL before 3.10.2 the function fp_mul_comba makes it easier to extract RSA key information for a malicious user who has access to view cache on a machine.
0
Attacker Value
Unknown

CVE-2016-7440

Disclosure Date: December 13, 2016 (last updated November 25, 2024)
The C software implementation of AES Encryption and Decryption in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover AES keys by leveraging cache-bank timing differences.
Attacker Value
Unknown

CVE-2016-7438

Disclosure Date: December 13, 2016 (last updated November 25, 2024)
The C software implementation of ECC in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging cache-bank hit differences.
0
Attacker Value
Unknown

CVE-2016-7439

Disclosure Date: December 13, 2016 (last updated November 25, 2024)
The C software implementation of RSA in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging cache-bank hit differences.
0
Attacker Value
Unknown

CVE-2015-6925

Disclosure Date: January 22, 2016 (last updated November 25, 2024)
wolfSSL (formerly CyaSSL) before 3.6.8 allows remote attackers to cause a denial of service (resource consumption or traffic amplification) via a crafted DTLS cookie in a ClientHello message.
0
Attacker Value
Unknown

CVE-2015-7744

Disclosure Date: January 22, 2016 (last updated November 25, 2024)
wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack.
Attacker Value
Unknown

CVE-2012-1897

Disclosure Date: October 01, 2012 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in Wolf CMS 0.75 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) delete users via the user id number to admin/user/delete; (2) delete pages via the page id number to admin/page/delete; delete the (3) images or (4) themes directory via the directory name to admin/plugin/file_manager/delete, and possibly other directories; or (5) logout the user via a request to admin/login/logout.
0
Attacker Value
Unknown

CVE-2012-1898

Disclosure Date: October 01, 2012 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in wolfcms/admin/user/add in Wolf CMS 0.75 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user[name], (2) user[email], or (3) user[username] parameters.
0
Attacker Value
Unknown

CVE-2006-6778

Disclosure Date: December 28, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in shownews.php in TimberWolf 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the nid parameter.
0