CVE-2024-44793
- EPSS 0.24%
- Veröffentlicht 26.08.2024 20:15:08
- Zuletzt bearbeitet 05.09.2024 18:28:42
A cross-site scripting (XSS) vulnerability in the component /managers/multiple_freeleech.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the torrents parameter.
CVE-2024-44795
- EPSS 0.26%
- Veröffentlicht 26.08.2024 20:15:08
- Zuletzt bearbeitet 05.09.2024 18:26:41
A cross-site scripting (XSS) vulnerability in the component /login/disabled.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter.
CVE-2024-44797
- EPSS 0.26%
- Veröffentlicht 26.08.2024 20:15:08
- Zuletzt bearbeitet 06.09.2024 22:27:16
A cross-site scripting (XSS) vulnerability in the component /managers/enable_requests.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the view parameter.
CVE-2017-7247
- EPSS 0.32%
- Veröffentlicht 23.03.2017 22:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Multiple Cross-Site Scripting (XSS) were discovered in Gazelle before 2017-03-19. The vulnerabilities exist due to insufficient filtration of user-supplied data (torrents, size) passed to the 'Gazelle-master/sections/tools/managers/multiple_freeleech...
CVE-2017-7248
- EPSS 0.32%
- Veröffentlicht 23.03.2017 22:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
A Cross-Site Scripting (XSS) was discovered in Gazelle before 2017-03-19. The vulnerability exists due to insufficient filtration of user-supplied data (type) passed to the 'Gazelle-master/sections/better/transcode.php' URL. An attacker could execute...
CVE-2017-7249
- EPSS 0.32%
- Veröffentlicht 23.03.2017 22:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Multiple Cross-Site Scripting (XSS) were discovered in Gazelle before 2017-03-19. The vulnerabilities exist due to insufficient filtration of user-supplied data (action, userid) passed to the 'Gazelle-master/sections/tools/data/ocelot_info.php' URL. ...
CVE-2017-7250
- EPSS 0.32%
- Veröffentlicht 23.03.2017 22:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
A Cross-Site Scripting (XSS) was discovered in Gazelle before 2017-03-19. The vulnerability exists due to insufficient filtration of user-supplied data (action) passed to the 'Gazelle-master/sections/tools/finances/bitcoin_balance.php' URL. An attack...