Show filters
95 Total Results
Displaying 81-90 of 95
Sort by:
Attacker Value
Unknown
CVE-2018-4050
Disclosure Date: April 01, 2019 (last updated November 27, 2024)
An exploitable local privilege escalation vulnerability exists in the privileged helper tool of GOG Galaxy's Games, version 1.2.47 for macOS. An attacker can globally adjust folder permissions leading to execution of arbitrary code with elevated privileges.
0
Attacker Value
Unknown
CVE-2019-7720
Disclosure Date: February 11, 2019 (last updated November 27, 2024)
taocms through 2014-05-24 allows eval injection by placing PHP code in the install.php db_name parameter and then making a config.php request.
0
Attacker Value
Unknown
CVE-2018-20303
Disclosure Date: December 20, 2018 (last updated November 27, 2024)
In pkg/tool/path.go in Gogs before 0.11.82.1218, a directory traversal in the file-upload functionality can allow an attacker to create a file under data/sessions on the server, a similar issue to CVE-2018-18925.
0
Attacker Value
Unknown
CVE-2018-18925
Disclosure Date: November 04, 2018 (last updated November 27, 2024)
Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery in the file session provider in file.go. This is related to session ID handling in the go-macaron/session code for Macaron.
0
Attacker Value
Unknown
CVE-2018-17031
Disclosure Date: September 14, 2018 (last updated November 27, 2024)
In Gogs 0.11.53, an attacker can use a crafted .eml file to trigger MIME type sniffing, which leads to XSS, as demonstrated by Internet Explorer, because an "X-Content-Type-Options: nosniff" header is not sent.
0
Attacker Value
Unknown
CVE-2018-16409
Disclosure Date: September 03, 2018 (last updated November 27, 2024)
In Gogs 0.11.53, an attacker can use migrate to send arbitrary HTTP GET requests, leading to SSRF.
0
Attacker Value
Unknown
CVE-2018-15193
Disclosure Date: August 08, 2018 (last updated November 27, 2024)
A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via a crafted issue / link.
0
Attacker Value
Unknown
CVE-2018-15192
Disclosure Date: August 08, 2018 (last updated November 27, 2024)
An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.
0
Attacker Value
Unknown
CVE-2018-15178
Disclosure Date: August 08, 2018 (last updated November 27, 2024)
Open redirect vulnerability in Gogs before 0.12 allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via an initial /\ substring in the user/login redirect_to parameter, related to the function isValidRedirect in routes/user/auth.go.
0
Attacker Value
Unknown
CVE-2011-5295
Disclosure Date: January 01, 2015 (last updated October 05, 2023)
Buffer overflow in the Download method in a certain ActiveX control in MDIEEx.dll in Gogago YouTube Video Converter 1.1.6 allows remote attackers to execute arbitrary code via a long argument.
0