Vulnerabilities
Vulnerable Software
Zend:  >> Zendto  >> 5.20-3  Security Vulnerabilities
ZendTo before 6.06-4 Beta allows XSS during the display of a drop-off in which a filename has unexpected characters.
CVSS Score
6.1
EPSS Score
0.003
Published
2021-03-02
lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header.
CVSS Score
7.5
EPSS Score
0.002
Published
2020-03-24
ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality.
CVSS Score
8.8
EPSS Score
0.003
Published
2020-03-24
lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta failed to properly check for equality when validating the session cookie, allowing an attacker to gain administrative access with a large number of requests.
CVSS Score
9.8
EPSS Score
0.009
Published
2020-03-24


Contact Us

Shodan ® - All rights reserved