VYPR
Vendor
Products
1
CVEs
4
Across products
4
Status
Private

Products

1

Recent CVEs

4
CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-1000125Hig0.497.50.00Nov 17, 2017Codiad(full version) is vulnerable to write anything to configure file in the installation resulting upload a webshell.
CVE-2014-95810.040.12Jan 8, 2015Directory traversal vulnerability in components/filemanager/download.php in Codiad 2.4.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter. NOTE: this issue was originally incorrectly mapped to CVE-2014-1137; see CVE-2014-1137 for more information.
CVE-2014-95820.030.01Jan 8, 2015Cross-site scripting (XSS) vulnerability in components/filemanager/dialog.php in Codiad 2.4.3 allows remote attackers to inject arbitrary web script or HTML via the short_name parameter in a rename action. NOTE: this issue was originally incorrectly mapped to CVE-2014-1137; see CVE-2014-1137 for more information.
CVE-2013-72570.000.00Jan 3, 2014Cross-site scripting (XSS) vulnerability in Codiad 2.0.7 allows remote attackers to inject arbitrary web script or HTML via the Project Name field.