Easyctf
by Kozos
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2015-0914 | 0.00 | — | 0.00 | May 1, 2015 | EasyCTF before 1.4 does not validate the session ID, which allows remote attackers to obtain access via a crafted HTTP request. | |||
| CVE-2015-0913 | 0.00 | — | 0.00 | May 1, 2015 | Cross-site scripting (XSS) vulnerability in EasyCTF before 1.4 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |||
| CVE-2015-0912 | 0.00 | — | 0.00 | May 1, 2015 | EasyCTF before 1.4 allows remote authenticated users to write executable content to files via unspecified vectors. |
- CVE-2015-0914May 1, 2015risk 0.00cvss —epss 0.00
EasyCTF before 1.4 does not validate the session ID, which allows remote attackers to obtain access via a crafted HTTP request.
- CVE-2015-0913May 1, 2015risk 0.00cvss —epss 0.00
Cross-site scripting (XSS) vulnerability in EasyCTF before 1.4 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
- CVE-2015-0912May 1, 2015risk 0.00cvss —epss 0.00
EasyCTF before 1.4 allows remote authenticated users to write executable content to files via unspecified vectors.