VYPR

Media Server

by Plexcor

CVEs (2)

  • CVE-2014-9181Dec 2, 2014
    risk 0.04cvss epss 0.15

    Multiple directory traversal vulnerabilities in Plex Media Server before 0.9.9.3 allow remote attackers to read arbitrary files via a .. (dot dot) in the URI to (1) manage/ or (2) web/ or remote authenticated users to read arbitrary files via a .. (dot dot) in the URI to resources/.

  • CVE-2014-9304Dec 7, 2014
    risk 0.03cvss epss 0.03

    Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrative actions via multiple crafted X-Plex-Url headers to system/proxy, which are inconsistently processed by the request handler in the backend web server.