CVE-2017-15608
Published Sep 26, 2018Inedo ProGet before 5.0 Beta5 has CSRF, allowing an attacker to change advanced settings.
Loading current evidence
Historical archive search
Search decades of CVEs by regex, severity, date, CWE, vendor/product tags, KEV, PoC, and other evidence.
Results
8 results · Sorted by Highest Buzz score first
Inedo ProGet before 5.0 Beta5 has CSRF, allowing an attacker to change advanced settings.
Indeo Otter through 1.7.4 mishandles a "</script>" substring in an initial DP payload, which allows remote attackers to cause a denial of service (crash) or possibly have unspecif…
Inedo Otter before 1.7.4 has directory traversal in filesystem-based rafts via vectors involving '/' characters or initial '.' characters, aka OT-181.
Inedo BuildMaster before 5.8.2 does not properly restrict creation of RequireManageAllPrivileges event listeners.
An Open Redirect vulnerability in Inedo BuildMaster before 5.8.2 allows remote attackers to redirect users to arbitrary web sites.
Inedo BuildMaster before 5.8.2 has XSS.
In Inedo BuildMaster before 5.8.2, XslTransform was used where XslCompiledTransform should have been used.
Inedo ProGet before 4.7.14 does not properly address dangerous package IDs during package addition, aka PG-1060.
Every filter state lives in the URL so you can bookmark, share, and crawl exact historical slices instead of a client-only search session.
Buzz order uses the latest all-time evidence snapshot, refreshed every two hours. Evidence-bearing CVEs rank first; records without a snapshot continue newest-first.