CVE-2017-15608
Published Sep 26, 2018Inedo ProGet before 5.0 Beta5 has CSRF, allowing an attacker to change advanced settings.
Vendor archive
8 CVEs tagged to vendor inedo — 3 Critical, 2 High, 3 Medium, 0 Low, 0 Unrated.
Inedo ProGet before 5.0 Beta5 has CSRF, allowing an attacker to change advanced settings.
Indeo Otter through 1.7.4 mishandles a "</script>" substring in an initial DP payload, which allows remote attackers to cause a denial of service (crash) or possibly have unspecif…
Inedo Otter before 1.7.4 has directory traversal in filesystem-based rafts via vectors involving '/' characters or initial '.' characters, aka OT-181.
Inedo BuildMaster before 5.8.2 does not properly restrict creation of RequireManageAllPrivileges event listeners.
An Open Redirect vulnerability in Inedo BuildMaster before 5.8.2 allows remote attackers to redirect users to arbitrary web sites.
Inedo BuildMaster before 5.8.2 has XSS.
In Inedo BuildMaster before 5.8.2, XslTransform was used where XslCompiledTransform should have been used.
Inedo ProGet before 4.7.14 does not properly address dangerous package IDs during package addition, aka PG-1060.