Show filters
224 Total Results
Displaying 111-120 of 224
Sort by:
Attacker Value
Unknown
CVE-2013-2009
Disclosure Date: February 07, 2020 (last updated February 21, 2025)
WordPress WP Super Cache Plugin 1.2 has Remote PHP Code Execution
0
Attacker Value
Unknown
CVE-2013-2008
Disclosure Date: February 07, 2020 (last updated February 21, 2025)
WordPress Super Cache Plugin 1.3 has XSS.
0
Attacker Value
Unknown
CVE-2020-5202
Disclosure Date: January 21, 2020 (last updated November 27, 2024)
apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /usr/lib/apt-cacher-ng/acngtool program attempts to connect to apt-cacher-ng via TCP on localhost port 3142, even if the explicit SocketPath=/var/run/apt-cacher-ng/socket command-line option is passed. The cron job /etc/cron.daily/apt-cacher-ng (which is active by default) attempts this periodically. Because 3142 is an unprivileged port, any local user can try to bind to this port and will receive requests from acngtool. There can be sensitive data in these requests, e.g., if AdminAuth is enabled in /etc/apt-cacher-ng/security.conf. This sensitive data can leak to unprivileged local users that manage to bind to this port before the apt-cacher-ng daemon can.
0
Attacker Value
Unknown
CVE-2019-10778
Disclosure Date: January 08, 2020 (last updated February 21, 2025)
devcert-sanscache before 0.4.7 allows remote attackers to execute arbitrary code or cause a Command Injection via the exec function. The variable `commonName` controlled by user input is used as part of the `exec` function without any sanitization.
0
Attacker Value
Unknown
CVE-2013-2011
Disclosure Date: December 26, 2019 (last updated November 27, 2024)
WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attackers to inject arbitrary code. This issue exists because of an incomplete fix for CVE-2013-2009.
0
Attacker Value
Unknown
Object injection in cookie driver
Disclosure Date: December 12, 2019 (last updated November 27, 2024)
In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver.
0
Attacker Value
Unknown
CVE-2012-6078
Disclosure Date: November 22, 2019 (last updated November 27, 2024)
W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes.
0
Attacker Value
Unknown
CVE-2012-6077
Disclosure Date: November 22, 2019 (last updated November 27, 2024)
W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database cache files.
0
Attacker Value
Unknown
CVE-2012-6079
Disclosure Date: November 22, 2019 (last updated November 27, 2024)
W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this information via their hash keys.
0
Attacker Value
Unknown
CVE-2019-15892
Disclosure Date: September 03, 2019 (last updated November 08, 2023)
An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to trigger an assert by sending crafted HTTP/1 requests. The assert will cause an automatic restart with a clean cache, which makes it a Denial of Service attack.
0