FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-04-16 19:33:48 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
7313b0e3-27b4-11e5-a15a-50af736ef1c0pivotx -- Multiple unrestricted file upload vulnerabilities

Pivotx reports:

Multiple unrestricted file upload vulnerabilities in fileupload.php in PivotX before 2.3.9 allow remote authenticated users to execute arbitrary PHP code by uploading a file with a (1) .php or (2) .php# extension, and then accessing it via unspecified vectors.


Discovery 2014-04-15
Entry 2015-07-11
pivotx
< 2.3.9

CVE-2014-0341
e454ca2f-f88d-11e0-b566-00163e01a509PivotX -- Remote File Inclusion Vulnerability of TimThumb

The PivotX team reports:

TimThumb domain name security bypass and insecure cache handling. PivotX before 2.3.0 includes a vulnerable version of TimThumb.

If you are still running PivotX 2.2.6, you might be vulnerable to a security exploit, that was patched previously. Version 2.3.0 doesn't have this issue, but any older version of PivotX might be vulnerable.


Discovery 2011-08-03
Entry 2011-10-17
pivotx
< 2.3.0

48963
https://secunia.com/advisories/45416/
14d846d6-27b3-11e5-a15a-50af736ef1c0pivotx -- cross-site scripting (XSS) vulnerability

pivotx reports:

cross-site scripting (XSS) vulnerability in the nickname (and possibly the email) field. Mitigated by the fact that an attacker must have a PivotX account.


Discovery 2014-04-15
Entry 2015-07-11
pivotx
< 2.3.9

CVE-2014-0341
0d3547ab-9b69-11e1-bdb1-525401003090PivotX -- 'ajaxhelper.php' Cross Site Scripting Vulnerability

High-Tech Bridge reports:

Input passed via the "file" GET parameter to /pivotx/ajaxhelper.php is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in administrator's browser session in context of the affected website.


Discovery 2012-05-09
Entry 2012-05-12
Modified 2012-05-14
pivotx
le 2.3.2

52159
CVE-2012-2274
https://www.htbridge.com/advisory/HTB23087
ae0e5835-3cad-11e0-b654-00215c6a37bbPivotX -- administrator password reset vulnerability

US CERT reports:

PivotX contains a vulnerability that allows an attacker to change the password of any account just by guessing the username. Version 2.2.4 has been reported to not be affected. This vulnerability is being exploited in the wild and users should immediately upgrade to 2.2.5 or later. Mitigation steps for users that have been compromised have been posted to the PivotX Support Community.


Discovery 2011-02-18
Entry 2011-02-20
pivotx
< 2.2.4

CVE-2011-1035