Skip to content
Noroxi

codiad records

14 published records for vendor codiad.

All records

14 records
  • Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.

    CriticalCVSS 9.8Proof of conceptEPSS 38%

    codiad · codiadJul 12, 2018

  • Codiad Web IDE through 2.8.4 allows PHP Code injection.

    CriticalCVSS 9.8Proof of conceptEPSS 19%

    codiad · codiadMar 16, 2020

  • components/filemanager/class.filemanager.php in Codiad before 2.8.4 is vulnerable to remote command execution because shell commands can be

    CriticalCVSS 9.8Proof of conceptEPSS 8%

    codiad · codiadAug 20, 2017

  • ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Side Request Forgery (CSRF) vulnerability was found in Codiad v1.7.8 and later.

    HighCVSS 8.8No exploitEPSS 2%

    codiad · codiadAug 24, 2020

  • Codiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file.

    HighCVSS 7.2Proof of conceptEPSS 18%

    codiad · codiadNov 21, 2018

  • ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Codiad 2.8.4 /componetns/user/class.user.php:Authenticate() is vulnerable in magic hash authentica

    HighCVSS 7.5No exploitEPSS 1%

    codiad · codiadJan 27, 2021

  • Codiad(full version) is vulnerable to write anything to configure file in the installation resulting upload a webshell.

    HighCVSS 7.5No exploitEPSS 1%

    codiad · codiadNov 17, 2017

  • Codiad process.php saveJSON information disclosure

    HighCVSS 7.5No exploitEPSS 1%

    codiad · codiadFeb 21, 2023

  • ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Server-Side Request Forgery (SSRF) vulnerability was found in Codiad v1.7.8 and later.

    HighCVSS 7.2No exploitEPSS 3%

    codiad · codiadAug 24, 2020

  • ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Site Scripting (XSS) vulnerability was found in Codiad v1.7.8 and later.

    MediumCVSS 6.1No exploitEPSS 1%

    codiad · codiadAug 25, 2020

  • CVE-2014-9581
    21Monitor

    Directory traversal vulnerability in components/filemanager/download.php in Codiad 2.4.3 allows remote attackers to read arbitrary files via

    MediumCVSS 5.0Proof of conceptEPSS 4%

    codiad · codiadJan 8, 2015

  • Codiad v2.8.4 allows reflected XSS via the components/market/dialog.php type parameter.

    MediumCVSS 5.4No exploitEPSS 0%

    codiad · codiadMar 21, 2024

  • CVE-2013-7257
    18Monitor

    Cross-site scripting (XSS) vulnerability in Codiad 2.0.7 allows remote attackers to inject arbitrary web script or HTML via the Project Name

    MediumCVSS 4.3No exploitEPSS 2%

    codiad · codiadJan 3, 2014

  • CVE-2014-9582
    17Monitor

    Cross-site scripting (XSS) vulnerability in components/filemanager/dialog.php in Codiad 2.4.3 allows remote attackers to inject arbitrary we

    MediumCVSS 4.3Proof of conceptEPSS 1%

    codiad · codiadJan 8, 2015