Skip to main content

Vendor/product archive

piwigo / lexiglot CVEs

Beta · best-effort

9 CVEs tagged to piwigo / lexiglot2 Critical, 4 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2014-8945

Published Jun 1, 2020

admin.php?page=projects in Lexiglot through 2014-11-20 allows command injection via username and password fields.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-8944

Published Jun 1, 2020

Lexiglot through 2014-11-20 allows XSS (Reflected) via the username, or XSS (Stored) via the admin.php?page=config install_name, intro_message, or new_file_content parameter.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8943

Published Jun 1, 2020

Lexiglot through 2014-11-20 allows SSRF via the admin.php?page=projects svn_url parameter.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-8941

Published Jun 1, 2020

Lexiglot through 2014-11-20 allows SQL injection via an admin.php?page=users&from_id= or admin.php?page=history&limit= URI.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-8940

Published Jun 1, 2020

Lexiglot through 2014-11-20 allows remote attackers to obtain sensitive information (names and details of projects) by visiting the /update.log URI.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8939

Published Jun 1, 2020

Lexiglot through 2014-11-20 allows remote attackers to obtain sensitive information (full path) via an include/smarty/plugins/modifier.date_format.php request if PHP has a non-rec…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8938

Published Jun 1, 2020

Lexiglot through 2014-11-20 allows local users to obtain sensitive information by listing a process because the username and password are on the command line.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-8937

Published Jun 1, 2020

Lexiglot through 2014-11-20 allows denial of service because api/update.php launches svn update operations that use a great deal of resources.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1