Skip to content
Noroxi

pyplate records

5 published records for vendor pyplate.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

5 records
  • CVE-2014-3854
    27Monitor

    Cross-site request forgery (CSRF) vulnerability in admin/addScript.py in Pyplate 0.08 allows remote attackers to hijack the authentication o

    MediumCVSS 6.8Proof of conceptEPSS 1%

    pyplate · pyplateAug 7, 2014

  • CVE-2014-3855
    21Monitor

    Directory traversal vulnerability in download.py in Pyplate 0.08 allows remote attackers to read arbitrary files via a ..

    MediumCVSS 5.0No exploitEPSS 2%

    pyplate · pyplateAug 7, 2014

  • CVE-2014-3852
    20Monitor

    Pyplate 0.08 does not include the HTTPOnly flag in a Set-Cookie header for the id cookie, which makes it easier for remote attackers to obta

    MediumCVSS 5.0No exploitEPSS 2%

    pyplate · pyplateAug 7, 2014

  • CVE-2014-3853
    20Monitor

    Pyplate 0.08 does not set the secure flag for the id cookie in an https session, which makes it easier for remote attackers to capture this

    MediumCVSS 5.0No exploitEPSS 1%

    pyplate · pyplateAug 7, 2014

  • usr/lib/cgi-bin/create_passwd_file.py in Pyplate 0.08 uses world-readable permissions for passwd.db, which allows local users to obtain the

    LowCVSS 2.1No exploitEPSS 0%

    pyplate · pyplateAug 7, 2014