Apache

Roller

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 14.04.2025 08:18:54
  • Zuletzt bearbeitet 03.06.2025 21:32:18

A session management vulnerability exists in Apache Roller before version 6.1.5 where active user sessions are not properly invalidated after password changes. When a user's password is changed, either by the user themselves or by an administrator, e...

  • EPSS 0.15%
  • Veröffentlicht 14.10.2024 09:15:04
  • Zuletzt bearbeitet 27.05.2025 19:37:34

Cross-site Resource Forgery (CSRF), Privilege escalation vulnerability in Apache Roller. On multi-blog/user Roller websites, by default weblog owners are trusted to publish arbitrary weblog content and this combined with a deficiency in Roller's CSRF...

  • EPSS 0.32%
  • Veröffentlicht 26.07.2024 09:15:09
  • Zuletzt bearbeitet 14.03.2025 17:15:42

Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name features in all versions of Apache Roller on all platforms allows an authenticated user to perform an XSS attack. Mitigation: if ...

  • EPSS 0.51%
  • Veröffentlicht 06.08.2023 08:15:09
  • Zuletzt bearbeitet 21.11.2024 08:11:59

Insufficient input validation and sanitation in Weblog Category name, Website About and File Upload features in all versions of Apache Roller on all platforms allows an authenticated user to perform an XSS attack. Mitigation: if you do not have Rolle...

  • EPSS 2.44%
  • Veröffentlicht 18.08.2021 08:15:06
  • Zuletzt bearbeitet 21.11.2024 06:09:08

User controlled `request.getHeader("Referer")`, `request.getRequestURL()` and `request.getQueryString()` are used to build and run a regex expression. The attacker doesn't have to use a browser and may send a specially crafted Referer header programm...

  • EPSS 0.98%
  • Veröffentlicht 15.07.2019 22:15:12
  • Zuletzt bearbeitet 21.11.2024 04:16:33

A Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller. Roller's Math Comment Authenticator did not property sanitize user input and could be exploited to perform Reflected Cross Site Scripting (XSS). The mitigation for this vul...

  • EPSS 0.47%
  • Veröffentlicht 28.05.2019 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:54:04

Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java SAX Parser to implement its XML-RPC interface and by default that parser supports external entities in...

Exploit
  • EPSS 14.78%
  • Veröffentlicht 10.10.2017 01:30:20
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.

  • EPSS 0.39%
  • Veröffentlicht 17.07.2017 13:18:03
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary Java code via crafted Velocity Text Language (aka VTL).

  • EPSS 2.01%
  • Veröffentlicht 07.12.2013 20:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to the search results in the (1) RSS and (2) Atom feed templates.