Skip to main content

Vendor archive

fomori CVEs

Beta · best-effort

2 CVEs tagged to vendor fomori0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2015-8310

Published Mar 27, 2017

Cross-site scripting (XSS) vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to inject arbitrary web script or HTML via the playlistname field when cre…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8309

Published Mar 27, 2017

Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary files via the "value" parameter to "download."

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1