Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2022-30288

Disclosure Date: May 04, 2022 (last updated November 08, 2023)
Agoo before 2.14.3 does not reject GraphQL fragment spreads that form cycles, leading to an application crash. NOTE: the vendor has disputed this on the grounds that it is not the server's responsibility to "enforce all the various ways a developer could write code with logic errors.
Attacker Value
Unknown

CVE-2020-35236

Disclosure Date: December 14, 2020 (last updated November 28, 2024)
The GitLab Webhook Handler in amazee.io Lagoon before 1.12.3 has incorrect access control associated with project deletion.
Attacker Value
Unknown

CVE-2020-7670

Disclosure Date: June 10, 2020 (last updated February 21, 2025)
agoo prior to 2.14.0 allows request smuggling attacks where agoo is used as a backend and a frontend proxy also being vulnerable. HTTP pipelining issues and request smuggling attacks might be possible due to incorrect Content-Length and Transfer encoding header parsing. It is possible to conduct HTTP request smuggling attacks where `agoo` is used as part of a chain of backend servers due to insufficient `Content-Length` and `Transfer Encoding` parsing.
Attacker Value
Unknown

CVE-2008-1798

Disclosure Date: April 15, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in forum/kietu/libs/calendrier.php in Dragoon 0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cal[lng] parameter.
0
Attacker Value
Unknown

CVE-2008-1773

Disclosure Date: April 14, 2008 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in includes/header.inc.php in Dragoon 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.
0