Show filters
62 Total Results
Displaying 61-62 of 62
Sort by:
Attacker Value
Unknown
CVE-2017-14611
Disclosure Date: April 10, 2018 (last updated November 26, 2024)
SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter, related to use of the discontinued aheinze/fetch_url_contents component.
0
Attacker Value
Unknown
CVE-2014-1861
Disclosure Date: February 18, 2014 (last updated October 05, 2023)
The client in Jetro COCKPIT Secure Browsing (JCSB) 4.3.1 and 4.3.3 does not validate the FileName element in an RDP_FILE_TRANSFER document, which allows remote JCSB servers to execute arbitrary programs by providing a .EXE extension.
0