Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2019-20062 MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until used). Yetishare after 4.5.4 Fix from $2,3002020-02-10 HIGH 8.8 CVE-2019-20059 payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from the sSortDir_0 parameter… Yetishare after 4.5.4 Fix from $1,9502020-02-10 HIGH 7.5 CVE-2019-20060 MFScripts YetiShare v3.5.2 through v4.5.4 places sensitive information in the Referer header. If this leaks, then third parties may discover password… Yetishare after 4.5.4 Fix from $1,9502020-02-10 HIGH 7.5 CVE-2019-20061 The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in cleartext. In… Yetishare after 4.5.4 Fix from $1,9502020-02-10 MEDIUM 5.3 CVE-2019-19805 _account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 takes a different amount of time to return depending on whether an email… Yetishare after 4.5.3 Fix from $1,6002019-12-30 MEDIUM 5.3 CVE-2019-19806 _account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 displays a message indicating whether an email address is configured for… Yetishare after 4.5.3 Fix from $1,6002019-12-30 CRITICAL 9.1 CVE-2019-19735 class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on microtime), wh… Yetishare after 4.5.3 Fix from $2,3002019-12-30 HIGH 8.8 CVE-2019-19734 _account_move_file_in_folder.ajax.php in MFScripts YetiShare 3.5.2 directly inserts values from the fileIds parameter into a SQL string. This allows … Yetishare after 3.5.2 Fix from $1,9502019-12-30 HIGH 8.8 CVE-2019-19737 MFScripts YetiShare 3.5.2 through 4.5.3 does not set the SameSite flag on session cookies, allowing the cookie to be sent in cross-site requests and … Yetishare after 4.5.3 Fix from $1,9502019-12-30 HIGH 7.5 CVE-2019-19739 MFScripts YetiShare 3.5.2 through 4.5.3 does not set the Secure flag on session cookies, allowing the cookie to be sent over cleartext channels. Yetishare after 4.5.3 Fix from $1,9502019-12-30 MEDIUM 6.1 CVE-2019-19736 MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which can potent… Yetishare after 4.5.3 Fix from $1,6002019-12-30 MEDIUM 6.1 CVE-2019-19738 log_file_viewer.php in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or encode the output from the lFile parameter on the page, which wou… Yetishare after 4.5.3 Fix from $1,6002019-12-30 HIGH 7.2 CVE-2019-19732 translation_manage_text.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 directly insert values from the aSortDir_0 … Yetishare after 4.5.3 Fix from $1,9502019-12-30 MEDIUM 6.1 CVE-2019-19733 _get_all_file_server_paths.ajax.php (aka get_all_file_server_paths.ajax.php) in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or encode t… Yetishare after 4.5.3 Fix from $1,6002019-12-30