Vulnerabilities
Vulnerable Software
Codiad:  >> Codiad  Security Vulnerabilities
components/filemanager/class.filemanager.php in Codiad before 2.8.4 is vulnerable to remote command execution because shell commands can be embedded in parameter values, as demonstrated by search_file_type.
CVSS Score
9.8
EPSS Score
0.415
Published
2017-08-21
Cross-site scripting (XSS) vulnerability in components/filemanager/dialog.php in Codiad 2.4.3 allows remote attackers to inject arbitrary web script or HTML via the short_name parameter in a rename action. NOTE: this issue was originally incorrectly mapped to CVE-2014-1137; see CVE-2014-1137 for more information.
CVSS Score
4.3
EPSS Score
0.005
Published
2015-01-08
Directory traversal vulnerability in components/filemanager/download.php in Codiad 2.4.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter. NOTE: this issue was originally incorrectly mapped to CVE-2014-1137; see CVE-2014-1137 for more information.
CVSS Score
5.0
EPSS Score
0.072
Published
2015-01-08
Cross-site scripting (XSS) vulnerability in Codiad 2.0.7 allows remote attackers to inject arbitrary web script or HTML via the Project Name field.
CVSS Score
4.3
EPSS Score
0.004
Published
2014-01-03


Contact Us

Shodan ® - All rights reserved