Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
6.8
CVE-2012-2380
- EPSS 1.59%
- Veröffentlicht 26.06.2012 10:23:41
- Zuletzt bearbeitet 16.06.2026 23:41:27
Multiple cross-site request forgery (CSRF) vulnerabilities in the admin/editor console in Apache Roller before 5.0.1 allow remote attackers to hijack the authentication of admins or editors by leveraging the HTTP POST functionality.
4.3
CVE-2008-6879
- EPSS 4.99%
- Veröffentlicht 30.07.2009 19:30:00
- Zuletzt bearbeitet 16.06.2026 23:03:09
Cross-site scripting (XSS) vulnerability in Apache Roller 2.3, 3.0, 3.1, and 4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action.