Show filters
35 Total Results
Displaying 31-35 of 35
Sort by:
Attacker Value
Unknown
CVE-2018-1999017
Disclosure Date: July 23, 2018 (last updated November 27, 2024)
Pydio version 8.2.0 and earlier contains a Server-Side Request Forgery (SSRF) vulnerability in plugins/action.updater/UpgradeManager.php Line: 154, getUpgradePath($url) that can result in an authenticated admin users requesting arbitrary URL's, pivoting requests through the server. This attack appears to be exploitable via the attacker gaining access to an administrative account, enters a URL into Upgrade Engine, and reloads the page or presses "Check Now". This vulnerability appears to have been fixed in 8.2.1.
0
Attacker Value
Unknown
CVE-2018-1999016
Disclosure Date: July 23, 2018 (last updated November 27, 2024)
Pydio version 8.2.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in ./core/vendor/meenie/javascript-packer/example-inline.php line 48; ./core/vendor/dapphp/securimage/examples/test.mysql.static.php lines: 114,118 that can result in an unauthenticated remote attacker manipulating the web client via XSS code injection. This attack appear to be exploitable via the victim openning a specially crafted URL. This vulnerability appears to have been fixed in version 8.2.1.
0
Attacker Value
Unknown
CVE-2015-3432
Disclosure Date: September 19, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in Pydio (formerly AjaXplorer) before 6.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Pydio XSS Vulnerabilities."
0
Attacker Value
Unknown
CVE-2015-3431
Disclosure Date: September 19, 2017 (last updated November 26, 2024)
Pydio (formerly AjaXplorer) before 6.0.7 allows remote attackers to execute arbitrary commands via unspecified vectors, aka "Pydio OS Command Injection Vulnerabilities."
0
Attacker Value
Unknown
CVE-2013-6227
Disclosure Date: December 27, 2014 (last updated October 05, 2023)
Unrestricted file upload vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly AjaXplorer) before 5.0.4 allows remote attackers to execute arbitrary code by uploading an executable file, and then accessing this file at a location specified by the format parameter of a move operation.
0